Currently, I am using Magento version 2.4.6-p8 on my website. When I run a Security Scan, the report shows the following issue:
Scan Name: API ACL
Scan Details: API ACL - Failed. API ACL Patch not detected (APPSEC-1679) [200]
When I investigated the issue, I found the following setting in the Magento backend:
"Please make sure that Configuration → Services → Magento Web API → Web API Security → Allow Anonymous Guest Access is set to 'Off'."
However, it is already set to No.
Can you please help me resolve this issue?
Solved! Go to Solution.
This is resolved.
There was issue due open the carts/mine/ API in custom module.