Authorization Bypass in AzuraCast Media Download Feature
CVE-2026-100853

8.2HIGH

Key Information:

Vendor

Azuracast

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-100853?

In AzuraCast versions before 0.23.8, the public On-Demand download endpoint does not properly validate access controls at the playlist level. This flaw allows unauthenticated users to exploit the download functionality by directly requesting audio files using valid identifiers, thereby circumventing the access restrictions set by the station operator. As a result, sensitive audio content that should remain restricted becomes accessible to unauthorized users.

Affected Version(s)

AzuraCast 0 < 0.23.8

AzuraCast 0.23.8

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ikkyu3
.