---
id: CVE-2026-82475
title: >-
  iFlytek astron-agent through 1.1.1 contains an authorization bypass
  vulnerability in the copyFlow endpoint that fails to validate workflow
  ownership
summary: >-
  iFlytek astron-agent through 1.1.1 contains an authorization bypass
  vulnerability in the copyFlow endpoint that fails to validate workflow
  ownership. Authenticated attackers can enumerate workflow identifiers and
  overwrite other tenants'…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-862
published: '2026-08-29'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:53:23.707'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82475'
references:
  - url: 'https://github.com/iflytek/astron-agent'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/iflytek/astron-agent/blob/v1.1.1/console/backend/toolkit/src/main/java/com/iflytek/astron/console/toolkit/service/workflow/WorkflowService.java
    label: disclosure@vulncheck.com
  - url: 'https://github.com/iflytek/astron-agent/issues/1590'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/iflytek-astron-agent-through-1.1.1-workflow-hijacking-via-missing-ownership-check
    label: disclosure@vulncheck.com
  - url: 'https://github.com/iflytek/astron-agent/issues/1590'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00448
epssPercentile: 0.36287
ingestedAt: '2026-08-30T12:52:24.090Z'
---

## Overview

iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwrite other tenants' workflows or copy private workflows to read their definitions.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
