CVE-2026-108548
Received Received - Intake

Authentication Bypass in AstronRPA OpenResty Gateway

Vulnerability report for CVE-2026-108548, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

AstronRPA through 1.1.6 contains an authentication bypass vulnerability in the OpenResty gateway's auth_handler.lua that accepts any Bearer token without validation. Unauthenticated attackers can send arbitrary Bearer values to reach /api/resource/ and /api/rpa-ai-service/ routes and spoof X-User-Id or user_id headers to act as any user.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
iflytek astron-rpa 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

AstronRPA through version 1.1.6 has an authentication bypass in its OpenResty gateway's auth_handler.lua. The system accepts any Bearer token in the Authorization header without validating it. Attackers can send arbitrary Bearer values to access protected routes like /api/resource/ and /api/rpa-ai-service/. They can also spoof X-User-Id or user_id headers to impersonate any user without proper authentication.

Detection Guidance

Check if your AstronRPA system uses OpenResty with auth_handler.lua. Send a request with an arbitrary Bearer token to /api/resource/ or /api/rpa-ai-service/ endpoints. If the request succeeds without proper validation, the vulnerability is present.

Impact Analysis

Unauthenticated attackers can bypass authentication to access sensitive data or perform actions as any user. They may steal information, modify data, or disrupt services by exploiting the lack of token validation. The impact includes unauthorized access to protected APIs and potential data breaches.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection and access control. GDPR mandates strict authentication and authorization controls to protect personal data. HIPAA requires safeguards to ensure only authorized users access protected health information. The lack of proper authentication could lead to non-compliance and regulatory penalties.

Mitigation Strategies

Upgrade AstronRPA to a version that fixes the auth_handler.lua vulnerability. If upgrading is not possible, modify the auth_handler.lua to properly validate Bearer tokens before processing requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108548. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart