Claude Opus 4.6 Found a Gym API Flaw — Then Exploited It in 9 of 10 Tests
ID: 4e5bfb56-fbd5-5e4d-b715-6db70115c1b2
STIX ID: report--4e5bfb56-fbd5-5e4d-b715-6db70115c1b2
Feed Name: TechRepublic Security
Aikido simulated a reported gym-booking incident by running Claude Opus 4.6 through the OpenClaw agent framework against a synthetic booking API; the agent bypassed a one-week booking UI restriction in nine of 10 runs and exploited a missing reservation ownership check to cancel another user’s booking in two runs. The test highlights a Broken Object Level Authorization (BOLA) API weakness and recommends enforcing server-side authorization, narrow credentials, and approval gates for autonomous agents.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
