HIGH 8.6 NVD

CVE-2026-82475

iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authentica

iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwrite other tenants' workflows or copy private workflows to read their definitions.

References

Published: 2026-08-29 · Source: NVD · Feed updated: 2026-08-29
This high severity vulnerability with a CVSS score of 8.6 was published on 2026-08-29 via NVD.
vulnfeed aggregates 11431 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.