Broken Access Control in AzuraCast Web Application
CVE-2026-100851
7.2HIGH
What is CVE-2026-100851?
A broken access control vulnerability in AzuraCast versions prior to 0.23.8 allows authenticated users with only the View Station Page permission to exploit the GET /api/station/{id}/vue/profile endpoint. This enables them to access sensitive information, including plaintext Icecast and Shoutcast admin passwords. With these credentials, attackers who possess view-only access can authenticate themselves to the Icecast admin interface without the necessary broadcasting permissions, significantly compromising the security of the affected systems.
Affected Version(s)
AzuraCast 0 < 0.23.8
AzuraCast 0.23.8
