Sceawere

Vulnerability Detail

CVE-2026-108548UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

AstronRPA Authentication Bypass Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
3h ago
Vendor
iflytek
Product
astron-rpa
Attack Type
Improper Authentication
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

AstronRPA through 1.1.6 contains an authentication bypass vulnerability in the OpenResty gateway's auth_handler.lua that accepts any Bearer token without validation. Unauthenticated attackers can send arbitrary Bearer values to reach /api/resource/ and /api/rpa-ai-service/ routes and spoof X-User-Id or user_id headers to act as any user.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-10-10T15:16:57.843Z",
  "pubdate": "2026-10-10T15:16:57.843Z",
  "executiveSummary": "AstronRPA versions through 1.1.6 are susceptible to a critical authentication bypass vulnerability originating from the OpenResty gateway.\nThe flaw resides within the auth_handler.lua script, which performs improper validation of Bearer tokens.\nThis vulnerability allows unauthenticated remote attackers to bypass security controls by providing arbitrary Bearer token strings.\nSuccessful exploitation enables unauthorized access to sensitive API endpoints, specifically /api/resource/ and /api/rpa-ai-service/.\nBy manipulating HTTP headers, such as X-User-Id or user_id, an attacker can perform identity spoofing, effectively impersonating any user within the system, including administrative accounts.\nThe risk is severe as it grants full access to RPA resources and services without requiring valid credentials, potentially leading to unauthorized data exposure, system manipulation, or complete compromise of the automation environment.",
  "technicalDetails": "The vulnerability is located in the OpenResty auth_handler.lua component of the AstronRPA architecture, which acts as the primary request interceptor and security enforcement layer for API traffic.\nThe root cause is a logic error in the authorization verification process; the script fails to cryptographically verify or structurally validate the authenticity of the Authorization: Bearer token provided in the request headers. Instead, the implementation implicitly trusts any provided Bearer string, rendering the authentication mechanism entirely ineffective.\nThe attack flow begins when an unauthenticated actor sends a specially crafted HTTP request to protected endpoints, specifically targeting /api/resource/ or /api/rpa-ai-service/.\nIn the absence of actual token validation, the attacker is not required to possess a valid JSON Web Token (JWT) or session credential. The attacker simply provides an arbitrary string in the Authorization header to satisfy the presence check.\nOnce the auth_handler.lua grants access based on this insufficient validation, the attacker can then inject spoofed identity headers into the request. Specifically, by including headers such as X-User-Id or user_id in the request payload, the attacker instructs the backend service to associate the request with a target user identity.\nBecause the OpenResty gateway acts as a trusted intermediary, the backend API services accept these spoofed headers as authoritative, allowing the attacker to perform actions as the impersonated user.\nThis vulnerability is classified as an authentication bypass and identity impersonation flaw, necessitating no privileges for exploitation. The attack is fully reachable over the network and requires no interaction from legitimate users.\nThe post-exploitation impact includes full unauthorized access to RPA-specific workflows, sensitive automation data, and administrative control over the application's internal functions, bypassing the intended security posture of the platform."
}
CVE-2026-108548: AstronRPA Authentication Bypass Vulnerability (HIGH Severity, CVSS: 7.3) | Sceawere