Missing Tenant Authorization in AstronRPA Allows Unauthorized Data Access
CVE-2026-108547
7.1HIGH
What is CVE-2026-108547?
AstronRPA versions up to 1.1.6 are impacted by a significant vulnerability due to a lack of necessary authorization checks within the robot-service. This flaw permits authenticated users to access shared variables belonging to other tenants via the get-batch-shared-var endpoint. By exploiting this weakness, attackers can systematically enumerate shared variable IDs and decrypt shared variables using their own tenant key, leading to the potential exposure of sensitive credentials stored in plaintext. Organizations utilizing AstronRPA are urged to assess their systems for this vulnerability and implement corrective measures promptly.
Affected Version(s)
astron-rpa 0 <= 1.1.6
