Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.6

CVE-2026-82475: iFlytek Astron-Agent allows attackers to access or change other users' workflows

CVE-2026-82475 · published 5 days ago
Summary

The Astron-Agent software up to version 1.1.1 does not verify that a user owns a workflow before allowing changes. As a result, a person who already has a login can view or overwrite other customers' workflow setups, potentially exposing sensitive business processes. Update to a newer version or apply the vendor’s patch and restrict access to trusted users.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
iflytek astron-agent <= 1.1.1
Original advisory text
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow ...
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwrite other tenants' workflows or copy private workflows to read their definitions.
Severity
8.6 High
CVSS 3.1: 8.1 (NVD)
CVSS 4.0: 8.6 (NVD)
CVSS 4.0: 8.6 (OSV)
Exploitation
EPSS <1%
Type
CWE-862Missing Authorization
Timeline
Published29 Aug 2026
Updated2 Sep 2026
First seen29 Aug 2026
Sources
CVE-2026-82475 · MITRE
Monitor software like this
Free during beta