Liquidsoap Configuration Exposure in AzuraCast by Vendor AzuraCast
CVE-2026-76836

8.7HIGH

Key Information:

Vendor

Azuracast

Status
Vendor
CVE Published:
24 August 2026

What is CVE-2026-76836?

AzuraCast exposes sensitive Liquidsoap custom configuration fields without enforcing strict permission controls, allowing unauthorized users to write configuration changes. The vulnerable endpoint improperly validates permissions, enabling users with minimal access rights to modify critical aspects of Liquidsoap scripts. This can potentially lead to execution of arbitrary operating system commands upon backend restarts, posing a significant security risk.

Affected Version(s)

AzuraCast 0 <= 0.23.8

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jaime RamĂ­rez (@JaimeRamirez-coder)
.