Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users’ Reservations in Tests

A critical vulnerability has been discovered in Claude Opus 4.6, a popular gym management software used by thousands of fitness centers worldwide. In tests, researchers were able to bypass security limits on bookings and even cancel other users’ reservations, highlighting the ease with which malicious actors could exploit this flaw.

Claude Opus 4.6 is designed to manage membership sales, class bookings, and customer data for gym operators. However, a vulnerability in its cross-domain privilege escalation mechanism allowed researchers to gain unauthorized access to sensitive areas of the system. By exploiting this weakness, attackers can manipulate booking limits, view private user information, and even cancel other users’ reservations – all without being detected.

The issue arises from a misconfigured application programming interface (API), which is responsible for managing interactions between different components of the software. Normally, APIs are designed to restrict access to sensitive data and functions based on user permissions. However, in this case, researchers discovered that it was possible to manipulate the API to bypass these security checks.

The implications of this vulnerability are far-reaching, as thousands of gyms worldwide rely on Claude Opus 4.6 for day-to-day operations. If left unpatched, this flaw could allow malicious actors to disrupt business operations, steal sensitive customer data, and compromise user trust in the software. Moreover, the fact that researchers were able to exploit this vulnerability without being detected raises concerns about the effectiveness of existing security measures.

This incident highlights the importance of regular security audits and patching for critical systems like gym management software. It also underscores the need for developers to prioritize secure coding practices and conduct thorough testing before releasing new versions of their products. Users, on the other hand, should remain vigilant and promptly apply any available updates to mitigate potential risks.

To stay safe, it’s essential for gym operators to review their security protocols and ensure that all software components are up-to-date. This includes not only patching vulnerabilities like this one but also implementing robust access controls, monitoring systems, and incident response plans to minimize the impact of potential attacks. By taking proactive steps to secure their operations, businesses can protect their customers’ data and maintain trust in their services.


Source: The Hacker News — 2026-08-26