Missing Tenant Authorization in AstronRPA Allows Unauthorized Data Access
CVE-2026-108547

7.1HIGH

Key Information:

Vendor

Iflytek

Vendor
CVE Published:
10 October 2026

What is CVE-2026-108547?

AstronRPA versions up to 1.1.6 are impacted by a significant vulnerability due to a lack of necessary authorization checks within the robot-service. This flaw permits authenticated users to access shared variables belonging to other tenants via the get-batch-shared-var endpoint. By exploiting this weakness, attackers can systematically enumerate shared variable IDs and decrypt shared variables using their own tenant key, leading to the potential exposure of sensitive credentials stored in plaintext. Organizations utilizing AstronRPA are urged to assess their systems for this vulnerability and implement corrective measures promptly.

Affected Version(s)

astron-rpa 0 <= 1.1.6

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.