GHSA-mcqv-c7v8-6mw4HighCVSS 6.5

AstronRPA through 1.1.6 contains a missing tenant authorization check in robot-service that...

Published
October 10, 2026
Last Modified
October 10, 2026

🔗 CVE IDs covered (1)

📋 Description

AstronRPA through 1.1.6 contains a missing tenant authorization check in robot-service that allows authenticated users to read other tenants' shared variables via the get-batch-shared-var endpoint. Attackers can enumerate sequential shared variable IDs and decrypt all-users variables re-encrypted with their own tenant key to recover other tenants' credentials in plaintext.

🔗 References (7)