{"id":"CVE-2026-108548","summary":"AstronRPA through 1.1.6 Authentication Bypass via Arbitrary Bearer Token","details":"AstronRPA through 1.1.6 contains an authentication bypass vulnerability in the OpenResty gateway's auth_handler.lua that accepts any Bearer token without validation. Unauthenticated attackers can send arbitrary Bearer values to reach /api/resource/ and /api/rpa-ai-service/ routes and spoof X-User-Id or user_id headers to act as any user.","modified":"2026-10-11T02:46:46.421956755Z","published":"2026-10-10T14:35:03.690Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/108xxx/CVE-2026-108548.json","cna_assigner":"VulnCheck","cwe_ids":["CWE-287"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/108xxx/CVE-2026-108548.json"},{"type":"PACKAGE","url":"https://github.com/iflytek/astron-rpa"},{"type":"ARTICLE","url":"https://github.com/iflytek/astron-rpa/blob/v1.1.6/backend/ai-service/app/dependencies/__init__.py#L10-L24"},{"type":"ARTICLE","url":"https://github.com/iflytek/astron-rpa/blob/v1.1.6/docker/volumes/nginx/lua/auth_handler.lua#L21-L35"},{"type":"REPORT","url":"https://github.com/iflytek/astron-rpa/issues/886"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-108548"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/astronrpa-through-1.1.6-authentication-bypass-via-arbitrary-bearer-token"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/iflytek/astron-rpa","events":[{"introduced":"0"},{"last_affected":"8b015bc1b15d23fbdc55c78ff1de9af4bb65fba6"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"1.1.6"}],"source":"AFFECTED_FIELD"}}],"versions":["v1.1.6","v1.1.5","v1.1.2-nightly","v1.0.0","v0.1.0-alpha"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-108548.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}]}