HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-82475 — iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerabilit...

·Source: NIST NVD

Updated:

Executive Summary

iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwrite other tenants' workflows or copy private workflows to read their definitions.

Analysis

iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwrite other tenants' workflows or copy private workflows to read their definitions. CVSS Score: 8.1. Published: 2026-08-29T17:18:00.057.

Indicators of Compromise (1)

CVE (1)
CVE-2026-82475
Source Attribution

Originally published by NIST NVD on Aug 29, 2026. Verified by: NIST.

Related Threats