HIGHVulnerability

CVE-2026-82475

iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwrite other tenants' workflows or copy private workflows to read their definitions.

Properties

severity
HIGH
score
8.1
epss_score
0.00255
cve_id
CVE-2026-82475
signal_observed_at
2026-09-15T21:12:48+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
published_at
2026-08-29T17:18:00.057
last_modified
2026-09-10T15:53:23.707
epss_percentile
0.17281

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Missing Authorization

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82475 — Ninja Signal Threat Intelligence | Ninja Signal