CVE-2026-108547
Last modified
CVE-2026-108547 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. AstronRPA through 1.1.6 contains a missing tenant authorization check in robot-service that allows authenticated users to read other tenants' shared variables via the get-batch-shared-var endpoint. Attackers can enumerate sequential shared variable IDs and decrypt all-users variables re-encrypted with their own tenant key to recover other tenants' credentials in plaintext..
Description
AstronRPA through 1.1.6 contains a missing tenant authorization check in robot-service that allows authenticated users to read other tenants' shared variables via the get-batch-shared-var endpoint. Attackers can enumerate sequential shared variable IDs and decrypt all-users variables re-encrypted with their own tenant key to recover other tenants' credentials in plaintext.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| iflytek | astron-rpa | <= 1.1.6 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-108547?
How severe is CVE-2026-108547?
How do I fix CVE-2026-108547?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-108541A vulnerability has been found in highwarden Super Store Fin…6.3
- CVE-2026-108542A vulnerability was found in 021is elvix-sdk up to 0.10.1. A…6.3
- CVE-2026-108543A vulnerability was determined in ag2ai ag2 up to 0.13.4. Af…6.3
- CVE-2026-108544A vulnerability was identified in Lippu Docx Reader Office V…6.3
- CVE-2026-108545SillyTavern 1.12.13 through 1.19.0 contains a denial of serv…5.9
- CVE-2026-108546Spotweb through 1.5.8 contains an OS command injection vulne…7.5
- CVE-2026-108548AstronRPA through 1.1.6 contains an authentication bypass vu…7.3
- CVE-2026-108549cc-connect through 1.5.0 contains a missing authentication v…8.1
- CVE-2026-10855An authorization flaw existed in the MISP Event Template Imp…4.3
- CVE-2026-108550SkillHub before 0.2.22 contains an incorrect authorization v…8.8
- CVE-2026-108551openapi-typescript-codegen through 0.31.0 contains a code in…9.8
- CVE-2026-108553OpenRefine through 3.10.1 contains a cross-site request forg…7.5
Are you affected by CVE-2026-108547?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
