Broken Access Control in AzuraCast Web Application
CVE-2026-100851

7.2HIGH

Key Information:

Vendor

Azuracast

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-100851?

A broken access control vulnerability in AzuraCast versions prior to 0.23.8 allows authenticated users with only the View Station Page permission to exploit the GET /api/station/{id}/vue/profile endpoint. This enables them to access sensitive information, including plaintext Icecast and Shoutcast admin passwords. With these credentials, attackers who possess view-only access can authenticate themselves to the Icecast admin interface without the necessary broadcasting permissions, significantly compromising the security of the affected systems.

Affected Version(s)

AzuraCast 0 < 0.23.8

AzuraCast 0.23.8

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alpastx
.