It's 2021. You download the Peloton app to track your workouts. You notice that your profile URL ends with a number — your user ID.
Out of curiosity, you change the number. You hit enter.
Someone else's profile loads. Their age. Their weight. Their location. Their workout history. Everything.
You didn't hack anything. You didn't write any code. You changed one number in a URL.
This wasn't a one-off. Every single Peloton account — over 4 million users — had their private data exposed this way. The vulnerability existed for months before anyone reported it. Peloton took another 3 months to fix it after being told.
You didn't need to know what this vulnerability is called to exploit it. All you needed was curiosity and a browser. That's what makes it the #1 API security risk in the world.