BOLA is the #1 API vulnerability because it is a missing check, not a bug. The deny-by-default, object-boundary authorization architecture that kills it.