Authentication Bypass in AstronRPA by Iflytek
CVE-2026-108548

6.9MEDIUM

Key Information:

Vendor

Iflytek

Vendor
CVE Published:
10 October 2026

What is CVE-2026-108548?

AstronRPA versions up to 1.1.6 are vulnerable due to an authentication bypass flaw within the OpenResty gateway's 'auth_handler.lua'. This vulnerability allows unauthenticated attackers to exploit the system by sending any Bearer token to the API endpoints, specifically '/api/resource/' and '/api/rpa-ai-service/'. Attackers can manipulate the 'X-User-Id' or 'user_id' headers, enabling them to impersonate any authorized user, thereby posing significant security risks to the application's integrity and data confidentiality.

Affected Version(s)

astron-rpa 0 <= 1.1.6

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.