A security researcher named OpenClaw discovered an API vulnerability allowing users to cancel other people's gym reservations. The flaw lacks basic authorization checks, enabling unauthorized queue manipulation. This incident highlights the persistent risks of insecure APIs. Developers must implement strict server-side validation to prevent simple identity spoofing in public-facing booking systems.