← Back to CVE List
CVE-2026-108548NVD
Vulnerability Summary
AstronRPA through 1.1.6 contains an authentication bypass vulnerability in the OpenResty gateway's auth_handler.lua that accepts any Bearer token without validation. Unauthenticated attackers can send arbitrary Bearer values to reach /api/resource/ and /api/rpa-ai-service/ routes and spoof X-User-Id or user_id headers to act as any user.
CVSS v4.0 Base Metrics — Score 6.9 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)Low
Integrity (Vulnerable System)Low
Availability (Vulnerable System)Low
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 7.3 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityLow
IntegrityLow
AvailabilityLow
Affected & Patched Versions
- iflytek astron-rpa <= 1.1.6
- iflytek astron-rpa 1.1.6
External References
- https://github.com/iflytek/astron-rpa/issues/886
- https://github.com/iflytek/astron-rpa
- https://github.com/iflytek/astron-rpa/blob/v1.1.6/docker/volumes/nginx/lua/auth_handler.lua#L21-L35
- https://github.com/iflytek/astron-rpa/blob/v1.1.6/backend/ai-service/app/dependencies/__init__.py#L10-L24
- https://www.vulncheck.com/advisories/astronrpa-through-1.1.6-authentication-bypass-via-arbitrary-bearer-token