The authorisation bug you will not find with a scanner
Broken object-level authorisation is the finding we report most often, and almost none of it is caught by automated tooling. Here is how we test for it by hand, and the three patterns that keep producing it.