OWASP found some form of broken access control in 100% of applications tested. In multi-tenant dashboards it usually looks like one specific mistake.
Credential abuse dropped to 13% of breaches in the 2026 DBIR. That is not the same as default passwords being gone, and here is where they still are.