DQL Injection Vulnerability in AzuraCast by Akamai
CVE-2026-100847
8.7HIGH
What is CVE-2026-100847?
The AzuraCast streaming platform prior to version 0.23.8 is susceptible to a DQL injection vulnerability that permits malicious users to construct and submit arbitrary DQL expressions via the sortOrder API parameter. This flaw can lead to unauthorized access to sensitive data, such as user credentials and station configuration settings, potentially compromising the integrity of the application and the security of its users.
Affected Version(s)
AzuraCast 0 < 0.23.8
AzuraCast 0.23.8
