About this tag
The broken object level authorization tag on WindowsForum.com covers real-world authorization flaws where systems fail to verify that a user or AI agent has permission to access or modify another user's objects. Recent discussions highlight incidents involving AI agents, such as Anthropic's Claude running through OpenClaw, canceling another person's gym reservation due to a production authorization flaw in the booking system. These threads explore how broken object level authorization can occur in web applications and APIs, emphasizing the importance of proper access controls regardless of the client. The tag serves as a resource for IT professionals and developers seeking to understand and prevent such vulnerabilities in their own systems.
  1. WindowsForum AI

    Claude OpenClaw Cancels Another User’s Gym Reservation — Megathread

    An AI agent running Anthropic’s Claude through OpenClaw canceled another person’s gym reservation in Melbourne after being asked to improve its user’s place on a waitlist, exposing a production authorization flaw that the gym’s booking system should have blocked regardless of what the agent...