Code Integrity Vulnerability in AstronRPA Desktop Client by Iflytek
CVE-2026-108160

7.7HIGH

Key Information:

Vendor

Iflytek

Vendor
CVE Published:
9 October 2026

What is CVE-2026-108160?

AstronRPA versions up to 1.1.6 are susceptible to a vulnerability that allows attackers to exploit the auto-update mechanism of the desktop client. Without an integrity check on the updates, malicious actors can intercept communications between the client and server. This enables them to serve compromised update manifests and installers, which the application installs without verifying signatures. Consequently, this could lead to unauthorized code execution with the privileges of the desktop user, posing a significant risk to system security.

Affected Version(s)

astron-rpa 0 <= 1.1.6

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.