Every other API security risk assumes authentication worked. Authorization, input validation, rate limiting — all of these assume you know who is making the request.
If authentication is broken, none of those other defenses matter. That's why it's #2.