A security researcher named OpenClaw discovered an API vulnerability allowing users to cancel other people's gym reservations without authorization. The flaw enabled a simple script to manipulate waitlists by deleting existing bookings. This highlights a persistent lack of basic access control in legacy web services now targeted by LLM-assisted auditing.