Red Team Training Starts 24th October, 2026
Technical Talk
Nobody Approved This : Hijacking Approval Authority Across AI Agents and Workflows
DATE
27 October 2026
LOCATION
Hilton EGL, Bangalore
TIME
16:45 - 17:30
Abstract
A single database row changes. A paused workflow resumes, and an AI agent quietly hands an attacker the keys to a whole cloud account. No credential stolen, no reviewer fooled, no code run on the host. The system did its job exactly as designed.
A workflow pauses for approval before a protected action. The attacker changes the stored decision and adds the approver identity the workflow expects. Resume runs under the workflow's own credential, and the audit trail records an approval that never happened. A rejected payment turns approved. A forged code review turns into an admin role.
The attacker has neither approval rights nor the protected credential. All they can do is write to the state the workflow trusts on resume. Effect escalates, access does not.
We tested 43 systems across AI agents, durable execution, CI/CD, code review, and identity governance. 30 exposed (26 directly, 3 conditionally, 1 transitively), 11 resistant, 2 without a qualifying gate.
Flowise confirmed one case as Moderate under a private GitHub Security Advisory and began remediation. Several vendors accepted or confirmed the mechanism and placed state integrity on the application or deployment. The framework trusts the stored decision, while the operator trusts the framework to guard the approval gate. No layer verifies where the approval came from, leaving the seam open and exploitable.
MEET THE INSTRUCTOR
Yuvraj Pradhan

Security Researcher
Yuvraj Pradhan is an AI systems engineer and independent security researcher working on agentic AI security and trust-boundary failures in production AI pipelines. His current research on approval-provenance failures spans 43 agent, durable-workflow, and CI/CD systems, with coordinated disclosures to Microsoft, OpenAI, AWS, and others. He is first author of Springer Nature research on a 125M-parameter NanoLLM and has spoken at MCP Dev Summit Bengaluru and Mumbai, both Linux Foundation events.
About AltSecCON
AltSecCON is an in-person Red Team training initiative focused on instructor-led delivery, enterprise-aligned labs, and practical offensive security execution.
© AltSecCON. An Altered Security initiative.
contact@alteredsecurity.com
Information
Training Programs
Follow Us
Conference
Event
© 2026 AltSecCON. All rights reserved.


