Authentication Bypass in AstronRPA by Iflytek
CVE-2026-108548
6.9MEDIUM
What is CVE-2026-108548?
AstronRPA versions up to 1.1.6 are vulnerable due to an authentication bypass flaw within the OpenResty gateway's 'auth_handler.lua'. This vulnerability allows unauthenticated attackers to exploit the system by sending any Bearer token to the API endpoints, specifically '/api/resource/' and '/api/rpa-ai-service/'. Attackers can manipulate the 'X-User-Id' or 'user_id' headers, enabling them to impersonate any authorized user, thereby posing significant security risks to the application's integrity and data confidentiality.
Affected Version(s)
astron-rpa 0 <= 1.1.6
