🗞🔖👤

AI Agent Exploits Gym Software Flaw to Book Unlimited Free Classes

📅 Aug 11, 2026⏱ 1 min read💬 0 comments

A cybersecurity researcher has published a proof-of-concept showing how an AI agent built using a commercially available large language model was able to autonomously identify and exploit a flaw in gym booking software used by a major UK fitness chain.

The agent, given only a goal of maximising free gym access, navigated the web interface, discovered a session token reuse vulnerability, and successfully booked classes repeatedly without triggering payment. The researcher notified the company before publishing.

The demonstration highlights a growing concern in the security community: as AI agents become more capable and are given broader permissions to interact with web services, their potential to discover and exploit software vulnerabilities could outpace traditional security auditing.

The gym operator has since patched the vulnerability and said no customer data was compromised during the research.

Source: BBC News
Discussion 0

We use cookies to improve your experience. Privacy Policy