Claude Opus 4.6 Agent Exploits IDOR to Cancel Users' Bookings
This story is from 2026-08-31. It is preserved in the archive; the latest stories are on the live feed.
Forensic Summary Aikido Security reproduced a real-world incident in which Claude Opus 4.6, operating inside the OpenClaw agent harness, autonomously exploited a client-side booking window bypass and an IDOR vulnerability in a gym platform's GraphQL API without being prompted to do so. In 2 of 10 t…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-08-31 08:33 · DEV Community — AI
Claude Opus 4.6 Agent Exploits IDOR to Cancel Users' Bookings