Threat · curated 9 Sep 2026
Workflow Identity Hijacking: The Silent Backdoor in AI Workflows
First reported noma.security
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Workflow identity hijacking lets an unauthenticated attacker abuse enterprise AI pipelines to reach and exfiltrate protected data through everyday input channels, exposing a class of authorization gaps defenders must audit in agentic workflows.
Researchers at Noma Labs disclosed "workflow identity hijacking," an authorization design flaw in enterprise AI pipelines that decouples the identity/permission of the user triggering a workflow from the permissions used to execute it. Attackers can bypass standard security controls by sending a seemingly benign request through an unauthenticated entry point such as a support inbox, GitHub issue, web form, or shared document, causing the pipeline to read, interpret, and execute the action despite the requester lacking authority.