Sceawere
Vulnerability Detail
CVE-2026-108864UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
iFlytek Astron Agent IDOR Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.2
- Creation Date
- 3h ago
- Vendor
- iflytek
- Product
- astron-agent
- Attack Type
- Authorization Bypass Through User-Controlled Key
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
iFlytek Astron Agent through 1.1.2 contains an insecure direct object reference vulnerability that allows authenticated applications to resume other applications' paused workflows by supplying their event_id to POST /workflow/v1/resume. Attackers can predict Snowflake event IDs to inject resume content into victim workflows and read their continuation output stream, breaking cross-tenant isolation.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.2",
"pubDate": "2026-10-11T14:17:06.500Z",
"pubdate": "2026-10-11T14:17:06.500Z",
"executiveSummary": "iFlytek Astron Agent versions through 1.1.2 are susceptible to an Insecure Direct Object Reference (IDOR) vulnerability within the workflow management subsystem.\nThe vulnerability resides in the POST /workflow/v1/resume endpoint, which fails to adequately validate the authorization context of the requester against the target resource.\nThis flaw enables authenticated attackers to resume and manipulate the workflows of other users or tenants by supplying predictable Snowflake-based event IDs.\nSuccessful exploitation results in a complete breach of cross-tenant isolation, allowing unauthorized actors to inject content into victim workflows and intercept continuation output streams.\nThe risk is critical, as it bypasses logical access controls, potentially leading to unauthorized data exposure, workflow hijacking, and the manipulation of downstream processes.\nExploitation requires authenticated access to the application but does not necessitate elevated administrative privileges, significantly lowering the barrier for potential attackers within the ecosystem.",
"technicalDetails": "The vulnerability is localized within the /workflow/v1/resume endpoint of the iFlytek Astron Agent application, which serves as the interface for resuming paused workflow executions.\nThe root cause is a failure of the server-side access control logic to perform a strict ownership check between the authenticated session identifier and the 'event_id' parameter provided in the request body.\nThe system utilizes predictable Snowflake IDs for event tracking. Because the backend relies on these IDs for object identification without verifying that the requester has explicit authorization to modify the associated workflow instance, the system is inherently prone to IDOR exploitation.\nThe attack flow begins when an attacker identifies or enumerates a valid 'event_id' associated with a victim's paused workflow. Due to the predictability of the Snowflake ID generation mechanism, an attacker can successfully guess or scan for target identifiers.\nOnce an 'event_id' is obtained, the attacker transmits a crafted POST request to the /workflow/v1/resume endpoint, substituting the 'event_id' field with the target's identifier.\nThe backend service processes the request and executes the resumption of the workflow in the context of the attacker's session, effectively attaching the attacker to a process they do not own.\nThis allows the attacker to inject malicious resume content into the workflow execution path. Furthermore, because the workflow's continuation output stream is returned to the requester, the attacker gains unauthorized visibility into the data processing lifecycle of the victim.\nBy manipulating these streams, an attacker can alter the state of the target application, extract sensitive output data, and break the expected security boundary of multi-tenant environments.\nThis behavior persists across all versions of the Astron Agent up to and including 1.1.2, representing a fundamental flaw in the handling of object-level authorization for state-managed resources."
}