HIGH 8.6 NVD
CVE-2026-82475
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authentica
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwrite other tenants' workflows or copy private workflows to read their definitions.
References
- https://github.com/iflytek/astron-agent
- https://github.com/iflytek/astron-agent/blob/v1.1.1/console/backend/toolkit/src/main/java/
- https://github.com/iflytek/astron-agent/issues/1590
- https://www.vulncheck.com/advisories/iflytek-astron-agent-through-1.1.1-workflow-hijacking
This high severity vulnerability with a CVSS score of 8.6 was published on 2026-08-29 via NVD.
vulnfeed aggregates 11431 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.