What happened
Verified via NVD REST API (published 2026-10-10, VulnCheck; CVSS 7.3): the gateway accepts any Bearer token and passes an arbitrary X-User-Id to the AI service. This pairs with the previously-reported AstronRPA smart-component chat XSS (CVE-2026-108159) to give a full unauthenticated-to-code-execution chain on the same platform.
Why it matters
AstronRPA is an AI-driven RPA product whose whole purpose is letting AI act on connected systems; an unauthenticated auth-bypass that lets anyone impersonate any user on its AI service routes is a direct compromise of the agent's authorization boundary.
Attack vector
The OpenResty gateway's auth_handler.lua accepts any Bearer token without validation, so unauthenticated attackers send an arbitrary Bearer value to reach protected /api/resource/ and /api/rpa-ai-service/ routes and spoof X-User-Id/user_id headers to impersonate any user (CWE-287).
Affected systems
iflytek/astron-rpa <= 1.1.6 (OpenResty auth_handler.lua; FastAPI dependencies)
Mitigation
No fixed release observed in the advisory; restrict the gateway to validate tokens against the AI service, drop Nginx-level trust of X-User-Id, and place the platform behind authenticated network controls until patched. See advisory PT-2026-109663 / VulnCheck.