A security researcher named OpenClaw discovered a critical authorization flaw in an Australian gym-booking website. The API allows users to cancel reservations belonging to others without verification. This vulnerability enables malicious actors to manipulate waitlists. Practitioners should prioritize strict server-side validation for all user-initiated resource deletions to prevent similar unauthorized access.