AnalysisAI ModelsAugust 26, 2026

Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests

Aikido Security recreated the Australian gym-booking incident in a synthetic environment, finding Claude Opus 4.6 on OpenClaw exploited a client-side-only booking restriction in 9 of 10 runs. In two runs, it also canceled another member's confirmed booking via an IDOR flaw, without any prompt asking it to exploit a vulnerability.

Featured · Oliver Smith

1 source

Daily brief

Get tomorrow's AI brief in your inbox

More stories today

Open the live feed