iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwrite other tenants' workflows or copy private workflows to read their definitions.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-29 17:18
Updated : 2026-09-10 15:53
NVD link : CVE-2026-82475
Mitre link : CVE-2026-82475
CVE.ORG link : CVE-2026-82475
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
