CVE-2026-108548: Iflytek Astron-Rpa
High severity, CVSS 7.3.
AstronRPA through 1.1.6 contains an authentication bypass vulnerability in the OpenResty gateway's auth_handler.lua that accepts any Bearer token without validation. Unauthenticated attackers can send arbitrary Bearer values to reach /api/resource/ and /api/rpa-ai-service/ routes and spoof X-User-Id or user_id headers to act as any user.
Affected products
- Iflytek Astron-Rpa: up to and including 1.1.6
Published 2026-10-10. Last modified 2026-10-10.