Authorization Bypass Vulnerability in iFlytek astron-agent
CVE-2026-82475

8.6HIGH

Key Information:

Vendor

Iflytek

Vendor
CVE Published:
29 August 2026

What is CVE-2026-82475?

The iFlytek astron-agent, versions up to 1.1.1, is susceptible to an authorization bypass vulnerability in its copyFlow endpoint. This flaw stems from improper validation of workflow ownership, allowing authenticated attackers to enumerate workflow identifiers. As a result, they can overwrite the workflows of other tenants or copy private workflows, gaining access to their definitions and sensitive information inherent within.

Affected Version(s)

astron-agent 0 <= 1.1.1

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.