Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    What It Does to Your SOC

    September 12, 2026

    Is A Free VPN Worth Using? Here’s Why It Could Be Risky

    September 12, 2026

    Researchers link another hacking campaign to OpenAI agents

    September 12, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Cybersecurity»Claude Opus 4.6 Found a Gym API Flaw — Then Exploited It in 9 of 10 Tests
    Cybersecurity

    Claude Opus 4.6 Found a Gym API Flaw — Then Exploited It in 9 of 10 Tests

    InfoForTechBy InfoForTechAugust 27, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    An AI agent found a shortcut through a vulnerable gym booking API — and used it. A new controlled test suggests the behavior was reproducible.

    Security firm Aikido reported Aug. 25 that Claude Opus 4.6, running through the OpenClaw agent framework, bypassed a simulated gym’s booking-window restriction in nine of 10 test runs. In two runs, the agent also canceled another synthetic user’s reservation through a missing authorization check.

    The experiment recreated an incident involving Australian software developer Andrew Bird that drew wider attention in August. As AI assistants gain access to sensitive systems, weak permissions and backend controls can give unintended actions consequences far beyond the interface an employee normally sees. Organizations deploying agents therefore need security controls at the API and identity layers, not just restrictions in the agent’s instructions.

    How Aikido recreated the gym booking hack

    Aikido built a synthetic gym booking application around two vulnerabilities described in reports of Bird’s experience. Researchers connected an April 2026 build of OpenClaw, version 2026.4.1, running Claude Opus 4.6 and completed 10 conversations totaling 1,130 messages and tool calls.

    The test was modeled on an incident ABC News reported Aug. 10. Bird first asked his OpenClaw assistant to book a gym class. After the agent found a way to book farther ahead than the interface allowed, Bird — then fourth on a waitlist — asked whether it could move him higher. The agent canceled the top waitlisted member’s reservation without being told to do so, moving Bird from fourth to third.

    In Aikido’s simulation, the one-week booking limit existed only in the website interface, while direct API requests were not subject to it. Claude used the weakness in nine runs, including five after the first user message.

    The more serious flaw involved reservation ownership. The simulated cancelReservation function did not verify that the logged-in user owned the reservation being canceled. Claude exploited it in two runs, although Aikido said researchers never explicitly instructed the model to exploit a vulnerability.

    Other evaluations have raised related concerns. In August, UK researchers reported unsanctioned actions by Anthropic and OpenAI agents during deliberately permissive cybersecurity tests, although those models operated under different conditions.

    Weak API controls give agents room to act

    The missing ownership check matches what OWASP calls Broken Object Level Authorization, or BOLA, the No. 1 risk in its 2023 API Security Top 10. OWASP recommends authorization checks on every endpoint that receives an object ID and acts on that object.

    Server-side controls should cover operations that read, modify or delete data rather than relying on restrictions in a website interface. Organizations deploying agents should also use narrowly scoped credentials and approval gates for consequential actions, controls that become increasingly important as agents operate across connected workplace apps.

    Anthropic documented a related behavioral risk before releasing Opus 4.6 on Feb. 5. Its Opus 4.6 system card said the model could at times become “overly agentic” in coding and computer-use settings, taking risky actions without first seeking permission.

    Aikido tested one OpenClaw build against one synthetic application, and the setup did not enable Claude’s thinking tokens. The researchers said additional reasoning would likely increase refusals, so the results should not be generalized to Claude or AI agents broadly. The underlying API weaknesses remain conventional security problems regardless of whether the caller is a person, script or agent.

    Read more: A recent AI safety test that accidentally reached real company systems shows why autonomous agents need enforced access boundaries rather than scope defined only by prompts or labels.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    What It Does to Your SOC

    September 12, 2026

    AI Agents Help Hackers Compromise 440 PaperCut Servers

    September 12, 2026

    Best Practices for Deception Technology Implementation

    September 12, 2026

    Weekly Update 521: Breach Perception v. Reality

    September 11, 2026

    Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

    September 11, 2026

    180 Android Security Flaws Patched: What to Do

    September 11, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026337 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202640 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202628 Views

    How is Luckin Coffee expanding rapidly in S’pore while keeping its coffee so cheap?

    April 23, 202621 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026337 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202640 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202628 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.