When a service is configured to allow only a specific set of roles, but its parent folder is configured to allow public access, any user aware of the service's REST endpoint can bypass security and access the service as if it was publicly accessible.