top of page

Red Team Training Starts 24th October, 2026

Technical Talk

Nobody Approved This : Hijacking Approval Authority Across AI Agents and Workflows

DATE

27 October 2026

LOCATION

Hilton EGL, Bangalore

TIME

16:45 - 17:30

Abstract

A single database row changes. A paused workflow resumes, and an AI agent quietly hands an attacker the keys to a whole cloud account. No credential stolen, no reviewer fooled, no code run on the host. The system did its job exactly as designed.

 

A workflow pauses for approval before a protected action. The attacker changes the stored decision and adds the approver identity the workflow expects. Resume runs under the workflow's own credential, and the audit trail records an approval that never happened. A rejected payment turns approved. A forged code review turns into an admin role.

​

The attacker has neither approval rights nor the protected credential. All they can do is write to the state the workflow trusts on resume. Effect escalates, access does not.​

Nobody Approved This.png

We tested 43 systems across AI agents, durable execution, CI/CD, code review, and identity governance. 30 exposed (26 directly, 3 conditionally, 1 transitively), 11 resistant, 2 without a qualifying gate.

​

Flowise confirmed one case as Moderate under a private GitHub Security Advisory and began remediation. Several vendors accepted or confirmed the mechanism and placed state integrity on the application or deployment. The framework trusts the stored decision, while the operator trusts the framework to guard the approval gate. No layer verifies where the approval came from, leaving the seam open and exploitable.

MEET THE INSTRUCTOR

Yuvraj Pradhan

Yuvraj Pradhan.png

Security Researcher 

Yuvraj Pradhan is an AI systems engineer and independent security researcher working on agentic AI security and trust-boundary failures in production AI pipelines. His current research on approval-provenance failures spans 43 agent, durable-workflow, and CI/CD systems, with coordinated disclosures to Microsoft, OpenAI, AWS, and others. He is first author of Springer Nature research on a 125M-parameter NanoLLM and has spoken at MCP Dev Summit Bengaluru and Mumbai, both Linux Foundation events.

About AltSecCON

AltSecCON is an in-person Red Team training initiative focused on instructor-led delivery, enterprise-aligned labs, and practical offensive security execution.
 

​© AltSecCON. An Altered Security initiative.
contact@alteredsecurity.com

Information

Training Programs

Follow Us

  • X
  • LinkedIn
  • Discord
  • Facebook
  • Instagram

Conference

Event

© 2026 AltSecCON. All rights reserved.

bottom of page