SQL Injection Vulnerability in zuraCast by AzuraCast
CVE-2026-67917
9.8CRITICAL
What is CVE-2026-67917?
The zuraCast product, developed by AzuraCast, is prone to an SQL injection vulnerability that affects versions 0.23.7 and prior. This flaw resides within the backup restore functionality, specifically in the azuracast:restore command, which executes SQL files extracted from backup archives without proper validation or sanitization of the contents. A remote attacker can exploit this weakness to escalate their privileges and potentially gain unauthorized access to sensitive data and functionalities. It is crucial for users of affected versions to review their security measures and update to a secure version.
