Missing Function Level Access Control vulnerability in ac-express and ac-spring-boot

Anyone ending up here in 2021, may also have a look at this post here (discusses the same issue):

And the open feature request here: [AC-2529] - Ecosystem Jira