SQL Injection Vulnerability in zuraCast by AzuraCast
CVE-2026-67917

9.8CRITICAL

Key Information:

Vendor

AzuraCast

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-67917?

The zuraCast product, developed by AzuraCast, is prone to an SQL injection vulnerability that affects versions 0.23.7 and prior. This flaw resides within the backup restore functionality, specifically in the azuracast:restore command, which executes SQL files extracted from backup archives without proper validation or sanitization of the contents. A remote attacker can exploit this weakness to escalate their privileges and potentially gain unauthorized access to sensitive data and functionalities. It is crucial for users of affected versions to review their security measures and update to a secure version.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.