Known Vulnerabilities in Role-based Authorization Strategy 2.6.1