An authorization logic flaw allowed badges to be granted without full role verification. This stemmed from incomplete role checks in the badge awarding process.