Ghostwire

CVE-2026-108547: AstronRPA through 1.1.6 contains a missing tenant authorization check in robot-service that allows authenticated users...

MEDIUM CVSS 6.5 Exploit Available

Published: October 10, 2026 | Last Modified: October 10, 2026

Description

AstronRPA through 1.1.6 contains a missing tenant authorization check in robot-service that allows authenticated users to read other tenants' shared variables via the get-batch-shared-var endpoint. Attackers can enumerate sequential shared variable IDs and decrypt all-users variables re-encrypted with their own tenant key to recover other tenants' credentials in plaintext.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

References