Description
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwrite other tenants' workflows or copy private workflows to read their definitions.
Published: 2026-08-29
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass → workflow hijacking and data leakage
Action: Immediate Patch
AI Analysis

Impact

iFlytek astron‑agent through version 1.1.1 contains an authorization bypass in the copyFlow endpoint. The endpoint does not verify that the authenticated user owns the workflow they are copying. As a result, a user can enumerate workflow identifiers, copy private workflows from other tenants, or overwrite workflow definitions belonging to other tenants, effectively allowing unauthorized modification and disclosure of confidential workflow configurations. The flaw is a classic example of CWE‑862: Missing Authorization.

Affected Systems

The affected product is iFlytek astron‑agent version 1.1.1 and earlier. Vulnerability applies to all deployments of that product that use the default copyFlow function. No specific environment constraints are listed; the issue relies on authenticated access to the API.

Risk and Exploitability

The vulnerability has a CVSS score of 8.6 indicating high severity. EPSS is not provided, so the current exploitation probability cannot be quantified, but the flaw requires only authenticated users, which many tenants will have. Because the attacker can impersonate other tenants' workflows, the risk is significant for multi‑tenant installations. The flaw is not currently listed in the CISA KEV catalog, but that does not reduce its potential impact.

Generated by OpenCVE AI on August 29, 2026 at 17:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest update from iFlytek that adds ownership validation to the copyFlow endpoint.
  • If a patch is not yet released, limit the copyFlow API to a trusted administrative group or protect it behind an API gateway that enforces tenant isolation.
  • Verify that workflow identifiers are not exposed through enumeration endpoints; remove or restrict any exposed listing of workflow IDs.

Generated by OpenCVE AI on August 29, 2026 at 17:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Iflytek
Iflytek astron-agent
Vendors & Products Iflytek
Iflytek astron-agent

Sat, 29 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwrite other tenants' workflows or copy private workflows to read their definitions.
Title iFlytek astron-agent through 1.1.1 Workflow Hijacking via Missing Ownership Check
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Iflytek Astron-agent
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-01T02:14:34.540Z

Reserved: 2026-08-29T14:11:14.664Z

Link: CVE-2026-82475

cve-icon Vulnrichment

Updated: 2026-09-01T02:14:28.944Z

cve-icon NVD

Status : Deferred

Published: 2026-08-29T17:18:00.057

Modified: 2026-09-10T15:53:23.707

Link: CVE-2026-82475

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T11:19:25Z

Weaknesses