{"data":{"id":"7eca17a9-35c4-47b5-b460-7798bdfb6656","title":"Quoting OpenClaw (running Opus 4.6)","summary":"A security researcher using OpenClaw (an AI system running Opus 4.6) discovered that a gym-booking website had a critical authorization flaw: the API lacked permission checks when canceling reservations, allowing anyone to cancel other users' bookings without proper authentication (verification of who you are). The researcher demonstrated this by canceling another person's reservation from the waitlist.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://simonwillison.net/2026/Aug/10/openclaw/","publishedAt":"2026-08-10T02:05:16.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"info","attackType":[],"issueType":"news","affectedPackages":null,"affectedVendors":["Anthropic"],"affectedVendorsRaw":["OpenClaw","Anthropic","Claude","Opus 4.6","OpenAI","Hugging Face"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-08-10T02:05:16.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.65,"researchCategory":null,"atlasIds":null}}