Sceawere
Vulnerability Detail
CVE-2026-108548UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
AstronRPA Authentication Bypass Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 3h ago
- Vendor
- iflytek
- Product
- astron-rpa
- Attack Type
- Improper Authentication
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
AstronRPA through 1.1.6 contains an authentication bypass vulnerability in the OpenResty gateway's auth_handler.lua that accepts any Bearer token without validation. Unauthenticated attackers can send arbitrary Bearer values to reach /api/resource/ and /api/rpa-ai-service/ routes and spoof X-User-Id or user_id headers to act as any user.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-10-10T15:16:57.843Z",
"pubdate": "2026-10-10T15:16:57.843Z",
"executiveSummary": "AstronRPA versions through 1.1.6 are susceptible to a critical authentication bypass vulnerability originating from the OpenResty gateway.\nThe flaw resides within the auth_handler.lua script, which performs improper validation of Bearer tokens.\nThis vulnerability allows unauthenticated remote attackers to bypass security controls by providing arbitrary Bearer token strings.\nSuccessful exploitation enables unauthorized access to sensitive API endpoints, specifically /api/resource/ and /api/rpa-ai-service/.\nBy manipulating HTTP headers, such as X-User-Id or user_id, an attacker can perform identity spoofing, effectively impersonating any user within the system, including administrative accounts.\nThe risk is severe as it grants full access to RPA resources and services without requiring valid credentials, potentially leading to unauthorized data exposure, system manipulation, or complete compromise of the automation environment.",
"technicalDetails": "The vulnerability is located in the OpenResty auth_handler.lua component of the AstronRPA architecture, which acts as the primary request interceptor and security enforcement layer for API traffic.\nThe root cause is a logic error in the authorization verification process; the script fails to cryptographically verify or structurally validate the authenticity of the Authorization: Bearer token provided in the request headers. Instead, the implementation implicitly trusts any provided Bearer string, rendering the authentication mechanism entirely ineffective.\nThe attack flow begins when an unauthenticated actor sends a specially crafted HTTP request to protected endpoints, specifically targeting /api/resource/ or /api/rpa-ai-service/.\nIn the absence of actual token validation, the attacker is not required to possess a valid JSON Web Token (JWT) or session credential. The attacker simply provides an arbitrary string in the Authorization header to satisfy the presence check.\nOnce the auth_handler.lua grants access based on this insufficient validation, the attacker can then inject spoofed identity headers into the request. Specifically, by including headers such as X-User-Id or user_id in the request payload, the attacker instructs the backend service to associate the request with a target user identity.\nBecause the OpenResty gateway acts as a trusted intermediary, the backend API services accept these spoofed headers as authoritative, allowing the attacker to perform actions as the impersonated user.\nThis vulnerability is classified as an authentication bypass and identity impersonation flaw, necessitating no privileges for exploitation. The attack is fully reachable over the network and requires no interaction from legitimate users.\nThe post-exploitation impact includes full unauthorized access to RPA-specific workflows, sensitive automation data, and administrative control over the application's internal functions, bypassing the intended security posture of the platform."
}