Severity Levels

Akto classifies API security vulnerabilities into four severity levels to help teams prioritize their remediation efforts. Each level indicates the potential impact on your API security posture and guides response timing.

Different Severity Levels

Severity Level
Description
Risk & Action Required

Critical

Issues that pose an immediate risk to API security.

Can lead to unauthorised data access, system compromise, or service disruption. Immediate remediation is essential.

High

Significant API security risks requiring prompt attention.

Not as immediately dangerous as Critical issues, but can severely impact API integrity and data security if exploited.

Medium

Moderate risks affecting specific API endpoints or security controls.

Should be remediated in a planned manner within standard development cycles.

Low

Minor API security concerns.

Do not pose immediate threats but represent opportunities to improve security during regular maintenance.

Update Severity for a Test Result

You can also update the severity of findings generated by a specific security test run.

Steps

1

Navigate to API Security TestingResults.

2

Open the preferred test run.

3

Select one or more tests whose severity you want to update.

4

Once selected, the Update Severity option appears at the bottom center of the screen.

5

Choose the updated severity level.

6

Click Update Severity to save.

circle-exclamation

Last updated