PatchSiren cyber security CVE debrief
CVE-2026-108548 iflytek CVE debrief
CVE-2026-108548 is an authentication bypass vulnerability in AstronRPA through version 1.1.6. The OpenResty gateway's auth_handler.lua accepts any Bearer token without validation, allowing unauthenticated attackers to access /api/resource/ and /api/rpa-ai-service/ routes and spoof X-User-Id or user_id headers to act as any user. This vulnerability allows attackers to bypass authentication and potentially gain unauthorized access to sensitive routes and data. Defenders should assess exposure and verify the authenticity of users and tokens to mitigate this vulnerability.
- Vendor
- iflytek
- Product
- astron-rpa
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders and administrators of AstronRPA deployments should assess exposure and verify the authenticity of users and tokens to mitigate this vulnerability. They should also restrict access to sensitive routes and monitor for suspicious activity. Additionally, they should review compensating controls for exposed systems and plan vendor-supported updates or mitigations through normal change control.
Why it matters
CVE-2026-108548 is an authentication bypass vulnerability in AstronRPA that allows unauthenticated attackers to access sensitive routes and spoof user headers. Defenders should prioritize verifying user authenticity and token validation, and restrict access to sensitive routes.
- Potential unauthorized access to sensitive routes
- Possible spoofing of user headers
- Required verification of user authenticity and token validation
- Potential for lateral movement
Technical summary
The OpenResty gateway's auth_handler.lua in AstronRPA through version 1.1.6 accepts any Bearer token without validation, allowing unauthenticated attackers to access sensitive routes and spoof user headers. This vulnerability can be mitigated by verifying the authenticity of users and tokens and restricting access to sensitive routes. The vulnerability is caused by a lack of validation in the auth_handler.lua script, which allows attackers to bypass authentication and potentially gain unauthorized access to sensitive routes and data.
Defensive priority
Defenders should prioritize verifying the authenticity of users and tokens, and restrict access to sensitive routes.
Recommended defensive actions
- Verify the authenticity of users and tokens
- Restrict access to sensitive routes
- Monitor for suspicious activity
- Review compensating controls for exposed systems
- Check relevant monitoring, detection, and logs for exposed assets
- Track exceptions and retest remediated assets
- Plan vendor-supported updates or mitigations through normal change control
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but the scope of affected versions and remediation steps require verification from official sources. The vulnerability is caused by the OpenResty gateway's auth_handler.lua accepting any Bearer token without validation. This lack of validation allows unauthenticated attackers to access sensitive routes and spoof user headers. The CVE record and NVD entry provide some information, but defenders should verify the authenticity of users and tokens and restrict access to /r
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108548 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108548
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108548 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108548
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/iflytek/astron-rpa
-
Source reference
Unverified legacy reference
URL: https://github.com/iflytek/astron-rpa/blob/v1.1.6/backend/ai-service/app/dependencies/__init__.py
-
Source reference
Unverified legacy reference
URL: https://github.com/iflytek/astron-rpa/blob/v1.1.6/docker/volumes/nginx/lua/auth_handler.lua
-
Source reference
Unverified legacy reference
URL: https://github.com/iflytek/astron-rpa/issues/886
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/astronrpa-through-1.1.6-authentication-bypass-via-arbitrary-bearer-token
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.