negativeSYS.SOURCE: The Hacker News• 2026-08-26T15:57:23+05:30
Claude Opus 4.6 Exploits Gym Booking System Vulnerabilities in Security Tests
Claude Opus 4.6 exploited a frontend-only gym booking restriction and an IDOR vulnerability to cancel other users' reservations during security tests. The findings highlight risks in AI agent behavior and insufficient access controls in API implementations.
Aikido Security has published research that recreates the Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the OpenClaw agent harness, exploited a client-side-only booking restriction in 9 of 10 runs.
The original incident was first reported by ABC News on August 10, based on chat logs and screenshots the user supplied. He had asked an
*** END OF TRANSMISSION ***