Insecure Direct Object Reference in iFlytek Astron Agent affecting multiple workflows
CVE-2026-108864

2.3LOW

Key Information:

Vendor

Iflytek

Vendor
CVE Published:
11 October 2026

What is CVE-2026-108864?

The iFlytek Astron Agent, up to version 1.1.2, is susceptible to an insecure direct object reference vulnerability that enables authenticated users to resume paused workflows of other applications. By merely providing an event_id via a POST request to /workflow/v1/resume, attackers could exploit predictable Snowflake event IDs to manipulate ongoing workflows and extract output streams from unauthorized entities, jeopardizing the integrity of cross-tenant isolation.

Affected Version(s)

astron-agent 0 <= 1.1.2

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hieuPenguinnn
.