🎄 Join our Annual Holiday wargame and win prizes!


Broken Auth.api is now a Medium Rank Challenge

16/01/2026

Broken Auth.api has officially earned its promotion to a Medium-difficulty challenge, and the numbers justify it. With a patch success rate of just 1%, this challenge has consistently exposed subtle but critical flaws in authentication logic that evade superficial fixes.

Participants are tasked with diagnosing and remediating a real-world authentication failure scenario, where naïve changes often introduce new bypasses or fail under adversarial conditions.

If you believe you can do better, now is your chance. Take on the Broken Auth.api challenge, apply a robust fix, and prove your AppSec skills by securing your position on the Holiday Wargame leaderboard.

Think you can fix it properly? Give it a shot.

:backhand_index_pointing_right: Try it now in the Holiday 7x7 Wargame

Deco line
Deco line

Play AppSec WarGames

Want to skill-up in secure coding and AppSec? Try SecDim Wargames to learn how to find, hack and fix security vulnerabilities inspired by real-world incidents.

Deco line
Deco line

Got a comment?

Join our secure coding and AppSec community. A discussion board to share and discuss all aspects of secure programming, AppSec, DevSecOps, fuzzing, cloudsec, AIsec code review, and more.

Read more