CVE-2026-108864
Received Received - Intake

Insecure Direct Object Reference in iFlytek Astron Agent

Vulnerability report for CVE-2026-108864, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

iFlytek Astron Agent through 1.1.2 contains an insecure direct object reference vulnerability that allows authenticated applications to resume other applications' paused workflows by supplying their event_id to POST /workflow/v1/resume. Attackers can predict Snowflake event IDs to inject resume content into victim workflows and read their continuation output stream, breaking cross-tenant isolation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
iflytek astron-agent 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

iFlytek Astron Agent through 1.1.2 has an insecure direct object reference flaw. Authenticated apps can resume other users' paused workflows by providing their event_id to POST /workflow/v1/resume. Attackers can guess Snowflake event IDs to inject resume content into victim workflows and read their output streams, breaking cross-tenant isolation.

Detection Guidance

To detect this vulnerability, monitor network traffic for unauthorized POST requests to /workflow/v1/resume endpoints. Check if event IDs from one application are being used to resume workflows in another application. Inspect logs for mismatches between the x-consumer-username header and the event's app_id.

Impact Analysis

An attacker could access sensitive data from other users' workflows by predicting event IDs. This could lead to unauthorized data exposure, workflow manipulation, or disruption of services relying on the Astron Agent.

Compliance Impact

This vulnerability could violate data protection regulations like GDPR or HIPAA by enabling unauthorized access to sensitive data. It undermines cross-tenant isolation, potentially leading to compliance breaches and legal consequences.

Mitigation Strategies

Update iFlytek Astron Agent to the latest version (1.1.2 or higher) to address the insecure direct object reference vulnerability. Ensure proper access controls are in place to prevent unauthorized workflow resumption. Monitor network traffic for suspicious POST requests to /workflow/v1/resume with unexpected event IDs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108864. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart