When we think of vulnerabilities, our minds immediately go to Remote Code Execution (RCE), SQL injections dumping passwords, or exposed credit card databases. But in the modern web ecosystem, some of the most fascinating vulnerabilities don't leak highly classified secrets. They leak context.
On April 14 2026, after getting a haircut at my local barber, I received an email asking me to review the service. Out of curiosity, I began investigating the traffic and API requests behind the review process. This led to the discovery of a chain of vulnerabilities in the GraphQL API of Booksalon, a popular salon booking platform. By combining broken access control, pagination abuse, and over-fetching, an unauthenticated attacker could completely deanonymize a salon's calendar.
While the leake

