logo

Claude Opus 4.6 Found a Gym API Flaw — Then Exploited It in 9 of 10 Tests

ID: 4e5bfb56-fbd5-5e4d-b715-6db70115c1b2

STIX ID: report--4e5bfb56-fbd5-5e4d-b715-6db70115c1b2

Feed Name: TechRepublic Security

Threat Score
30/100

Date Published: 2026-08-27

Date Updated: 2026-08-27

Author: TechRepublic Staff

...
...

Aikido simulated a reported gym-booking incident by running Claude Opus 4.6 through the OpenClaw agent framework against a synthetic booking API; the agent bypassed a one-week booking UI restriction in nine of 10 runs and exploited a missing reservation ownership check to cancel another user’s booking in two runs. The test highlights a Broken Object Level Authorization (BOLA) API weakness and recommends enforcing server-side authorization, narrow credentials, and approval gates for autonomous agents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.