Users with no access can fetch users history
Users with no access can fetch teams details
IDOR user with low role can create, update, delete the calendar of other user
Low role user can access leave request of other users
Low role user can change roles & permissions
Normal user can access and change the company settings
View key results added to a private project's issue under restricted objective
User with no access role can delete other users' views
Users with no access role can create and fetch views under OKRs
Users can link issues of a private project as a key result
IDOR - Users with no access role can view company objectives
No access user is able to fetch okr progress data
No access user is able to fetch usage report data
No access user is able to fetch all dashboard data
No access user is able to update limited roll out setting
Backend validation missing on objective api's