← Retour
CVE-2026-82475
high
CVSS 8.1
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow...
Résumé
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow...
Résumé IA openai / gpt-4o
Une vulnérabilité référencée **CVE-2026-82475** a été découverte dans CVE-2026-82475.
Des informations confidentielles peuvent être exposées. Score CVSS : 8.1/10.
Action : appliquez le correctif officiel de l'éditeur.
En cas de doute, contactez votre service informatique ou cherchez « CVE-2026-82475 CVE-2026-82475 » sur le site de l'éditeur.
CVE-2026-82475 (CVE-2026-82475) — CWE-862 / CVSS v3 8.1
Vecteur d'attaque : distant (réseau) / sans interaction utilisateur
Plan : 1) Audit SBOM, 2) Mise à jour staging→prod, 3) Surveillance WAF/proxy sur les endpoints affectés, 4) Recherche d'IOC dans les logs.
Réfs : voir GHSA / avis éditeur / version corrigée liés sur cette page.
❓ Quel est le problème
認可バイパス脆弱性です。
📍 Périmètre concerné
iFlytek astron-agent の copyFlow エンドポイントに存在します。
🔥 Gravité
認証された攻撃者により、他のテナントのワークフローを上書きされたり、プライベートワークフローのコピーと定義の読み取りが可能になります。CVSSスコアは8.1です。
🔧 Comment corriger
ワークフローの所有権を確実に検証するようにコードを修正してください。
🛡️ Contournement
情報なし
🔍 Détection
ワークフロー所有権のチェックコードを確認し、不備がないかを確認してください。
Références
- web https://github.com/iflytek/astron-agent
- web https://github.com/iflytek/astron-agent/blob/v1.1.1/console/backend/toolkit/src/main/java/com/iflytek/astron/console/toolkit/service/workflow/WorkflowService.java
- web https://github.com/iflytek/astron-agent/issues/1590
- web https://www.vulncheck.com/advisories/iflytek-astron-agent-through-1.1.1-workflow-hijacking-via-missing-ownership-check
- web https://nvd.nist.gov/vuln/detail/CVE-2026-82475
- web https://github.com/advisories/GHSA-87v8-76rg-m5w6