Back Redpacketsecurity CVE Alert: CVE-2026-100847 – AzuraCast
AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder API parameter of AbstractSearchableListAction.php. Attackers can inject arbitrary DQL expressions through the sortOrder parameter to extract sensitive database information including user credentials and station settings.
**Risk verdict:** Internet-facing installations warrant high priority; KEV, SSVC, exploit-code and EPSS status are not supplied, so active exploitation and priority-one status cannot be verified.
**Why this matters:** Unauthenticated access could expose credentials and station configuration, creating privacy, account-takeover and operational risks. Stolen credentials may support follow-on attacks against associated services, even though direct data modification or service disruption is not indicated.
**Most likely attack path:** An attacker sends a crafted sorting value to the exposed API; network access is sufficient, with no special conditions, existing privileges or victim interaction required. The assessed scope is unchanged, so direct impact appears confined to the vulnerable application and its data, although recovered credentials could enable wider access.
**Who is most exposed:** Self-hosted streaming platforms with public-facing management interfaces or APIs are most at risk. Deployments reachable only through trusted networks have lower exposure, but are not immune to internal threats.
Review API and reverse-proxy logs for unusual or malformed sorting values and database query errors.
Look for unexpected reads of account, credential or station-configuration records.
Check for suspicious use of exposed accounts after anomalous API requests.
Mitigation and prioritisation
Upgrade to the vendor-fixed release; prioritise internet-reachable instances and confirm the running build.
Restrict management/API access to trusted networks or a VPN while patching.
Review and rotate potentially exposed credentials; assess station settings for unauthorised disclosure.
Apply through normal change control, but expedite testing and deployment; reassess urgency when KEV, SSVC and EPSS data are available.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
