This exposes the authentication credentials in plaintext on the network and can lead to attackers finding and using the credentials to make unauthorized API calls.
This rule applies at the API Specification level (OAS/Swagger).
Man-in-the-Middle (MitM) Attacks: Attackers positioned between the client and server can modify or capture plaintext credentials exchanged during authentication, compromising security.