A security researcher named OpenClaw discovered an API vulnerability allowing users to cancel other people's gym reservations. The flaw lacked authorization checks, enabling unauthorized queue manipulation. This instance highlights the persistent risk of insecure APIs when integrated with automated tools. Developers must prioritize strict server-side validation to prevent simple unauthorized access attacks.