


Perceptive Security
SOC/SIEM Consultancy

iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authentica…
Published:
29 August 2026 at 00:00:00
Alert date:
29 August 2026 at 20:03:20
Source:
nvd.nist.gov
Enterprise Applications, Identity & Access, Web Technologies
iFlytek astron-agent through version 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint. The endpoint fails to validate workflow ownership, allowing authenticated attackers to enumerate workflow identifiers. Attackers can exploit this to overwrite other tenants' workflows or copy private workflows to read their definitions. This is a multi-tenant data isolation failure that enables cross-tenant data access and manipulation. The vulnerability is classified as an Insecure Direct Object Reference (IDOR) type flaw. It affects the WorkflowService.java component in the console backend toolkit. The issue has been reported via GitHub issues and documented by VulnCheck. No patch beyond version 1.1.1 is indicated in the advisory.
Technical details
Mitigation steps:
Affected products:
iFlytek astron-agent 1.1.1
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-82475
https://github.com/iflytek/astron-agent
https://github.com/iflytek/astron-agent/blob/v1.1.1/console/backend/toolkit/src/main/java/com/iflytek/astron/console/toolkit/service/workflow/WorkflowService.java
https://github.com/iflytek/astron-agent/issues/1590
https://www.vulncheck.com/advisories/iflytek-astron-agent-through-1.1.1-workflow-hijacking-via-missing-ownership-check
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
