CVE-2026-108547
Received Received - Intake

Authentication Bypass in AstronRPA via Shared Variables

Vulnerability report for CVE-2026-108547, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

AstronRPA through 1.1.6 contains a missing tenant authorization check in robot-service that allows authenticated users to read other tenants' shared variables via the get-batch-shared-var endpoint. Attackers can enumerate sequential shared variable IDs and decrypt all-users variables re-encrypted with their own tenant key to recover other tenants' credentials in plaintext.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
iflytek astron-rpa 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-108547 is a cross-tenant shared variable disclosure vulnerability in AstronRPA through version 1.1.6. It allows authenticated users to read other tenants' shared variables via the get-batch-shared-var endpoint due to a missing tenant authorization check. Attackers can enumerate sequential shared variable IDs and decrypt all-users variables re-encrypted with their own tenant key to recover other tenants' credentials in plaintext.

Detection Guidance

To detect this vulnerability, inspect network traffic for unauthorized access to the /robot-shared-var/get-batch-shared-var endpoint. Check logs for repeated requests with sequential shared variable IDs. Verify if tenant isolation is enforced in database queries like getAvailableByIds.

Impact Analysis

This vulnerability allows attackers to access sensitive data like credentials or configuration values belonging to other tenants. If exploited, it could lead to unauthorized data exposure, credential theft, or potential lateral movement within the system. The impact is significant as it bypasses tenant isolation, compromising data confidentiality across the platform.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection standards like GDPR and HIPAA, which mandate strict tenant data isolation and encryption. Unauthorized cross-tenant data access could result in regulatory penalties, loss of trust, and legal consequences due to compromised data confidentiality and integrity.

Mitigation Strategies

Immediately update AstronRPA to a patched version. Add tenant filters to the getAvailableByIds query to enforce tenant isolation. Validate and sanitize input data in the packageEncryptValue method to prevent injection attacks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108547. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart