PatchSiren cyber security CVE debrief
CVE-2026-82475 iflytek CVE debrief
The iFlytek astron-agent through version 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint. This vulnerability allows authenticated attackers to enumerate workflow identifiers and potentially overwrite other tenants' workflows or copy private workflows to read their definitions. Users of iFlytek astron-agent should be aware of this vulnerability and take steps to mitigate it, including verifying workflow ownership validation, restricting access to workflow identifiers and definitions, and implementing additional authentication and authorization checks. The CVE record was published on 2026-08-29T17:18:00.057Z and has not been modified since then.
- Vendor
- iflytek
- Product
- astron-agent
- CVSS
- HIGH 8.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-29
- Original CVE updated
- 2026-08-29
- Advisory published
- 2026-08-29
- Advisory updated
- 2026-08-29
Who should care
Users of iFlytek astron-agent through version 1.1.1 should be aware of this vulnerability and take steps to mitigate it. This includes verifying workflow ownership validation, restricting access to workflow identifiers and definitions, and implementing additional authentication and authorization checks. Affected operators, platforms, and security teams should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should also plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and review compensating controls for exposed systems while remediation is scheduled and verified. Additionally, they should check relevant monitoring, detection, and logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented. The iFlytek astron-agent through version 1.1.1 is affected, and users should take immediate action to mitigate the vulnerability. Security teams should prioritize this vulnerability based on its high CVSS score of 8.6 and take steps to protect their systems. Operators and platforms should also review their configurations and ensure that they are not exposed to this vulnerability. Vulnerability management teams should review the CVE record and assess the vulnerability's impact on their systems. They should also verify that their systems are not affected by this vulnerability or take steps to mitigate it if they are affected. The iFlytek astron-agent through version 1.1.1 is a critical system, and users should take immediate action to protect it from this vulnerability. The vulnerability's impact on the system can be significant, and users should take steps to prevent exploitation. The CVE record provides additional information about the vulnerability, and users should review it to understand the vulnerability's details. The iFlytek astron-agent through version 1.1.1 is a high-priority system, and users should take immediate action to protect it from this vulnerability. The vulnerability's CVSS score of 8.6 indicates its high severity, and users should take steps to protect
Technical summary
The iFlytek astron-agent through version 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint. This endpoint fails to validate workflow ownership, allowing authenticated attackers to enumerate workflow identifiers. As a result, attackers can overwrite other tenants' workflows or copy private workflows to read their definitions. The vulnerability is located in the copyFlow endpoint, which fails to validate workflow ownership. This allows authenticated attackers to enumerate workflow identifiers and potentially overwrite other tenants' workflows or copy private workflows to read their definitions.
Defensive priority
Authenticated attackers can exploit this vulnerability to overwrite workflows or read private workflow definitions.
Recommended defensive actions
- Verify workflow ownership validation in the copyFlow endpoint
- Restrict access to workflow identifiers and definitions
- Implement additional authentication and authorization checks
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE-2026-82475 record indicates an authorization bypass vulnerability in iFlytek astron-agent through 1.1.1. The vulnerability is located in the copyFlow endpoint, which fails to validate workflow ownership. This allows authenticated attackers to enumerate workflow identifiers and potentially overwrite other tenants' workflows or copy private workflows to read their definitions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-82475 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-82475
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-82475 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-82475
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/iflytek/astron-agent
-
Source reference
Unverified legacy reference
URL: https://github.com/iflytek/astron-agent/blob/v1.1.1/console/backend/toolkit/src/main/java/com/iflytek/astron/console/toolkit/service/workflow/WorkflowService.java
-
Source reference
Unverified legacy reference
URL: https://github.com/iflytek/astron-agent/issues/1590
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/iflytek-astron-agent-through-1.1.1-workflow-hijacking-via-missing-ownership-check
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.