CVE-2026-108864 PUBLISHED

iFlytek Astron Agent through 1.1.2 Authorization Bypass via /workflow/v1/resume Endpoint

Assigner: VulnCheck
Reserved: 11.10.2026 Published: 11.10.2026 Updated: 11.10.2026

iFlytek Astron Agent through 1.1.2 contains an insecure direct object reference vulnerability that allows authenticated applications to resume other applications' paused workflows by supplying their event_id to POST /workflow/v1/resume. Attackers can predict Snowflake event IDs to inject resume content into victim workflows and read their continuation output stream, breaking cross-tenant isolation.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 2.3

Product Status

Vendor iflytek
Product astron-agent
Versions Default: unaffected
  • affected from 0 to 1.1.2 (incl.)

Credits

  • hieuPenguinnn finder

References

Problem Types

  • Authorization Bypass Through User-Controlled Key CWE