Can somebody become one of your users?
Reset tokens that still work after they have been used, sessions that survive a password change, a login endpoint with nothing throttling it, a second factor that can be stepped around. Whatever the route, the end of it is the same: somebody else inside one of your accounts.
