{"data":{"id":"b65b025d-b438-45bc-b5d4-6b9c0676f278","title":"AI workflows may be creating a dangerous new authorization blind spot","summary":"Researchers have identified \"workflow identity hijacking,\" an attack where unauthenticated users can trigger privileged AI workflows by sending normal requests through unguarded entry points like support inboxes or web forms. The core problem is an authorization design flaw: the identity of the person who starts the workflow is separate from the identity used to execute it, allowing AI systems to perform high-privilege actions (like accessing financial data) using service account credentials instead of checking the requester's actual permissions.","solution":"N/A -- no mitigation discussed in source.","labels":["security","safety"],"sourceUrl":"https://www.csoonline.com/article/4220702/ai-workflows-may-be-creating-a-dangerous-new-authorization-blind-spot.html","publishedAt":"2026-09-10T12:04:44.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":[],"issueType":"news","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-09-10T12:04:44.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}