Code Injection Vulnerability in AzuraCast by AzuraCast
CVE-2026-100857

8.6HIGH

Key Information:

Vendor

Azuracast

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-100857?

AzuraCast, prior to version 0.23.4, is susceptible to a code injection flaw located within the ConfigWriter::cleanUpString() method. This vulnerability arises as the method does not sufficiently sanitize Liquidsoap string interpolation sequences. Authenticated users holding Media or Profile permissions can exploit this vulnerability to inject arbitrary Liquidsoap code into station configuration settings. Specifically, attackers can embed #{process.run()} expressions in playlist URLs or metadata fields, leading to the execution of shell commands at the azuracast user level upon station restart, thereby compromising the integrity and security of the affected systems.

Affected Version(s)

AzuraCast 0 < 0.23.4

AzuraCast 0.23.4

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

q1uf3ng
.