Skip to content
CVE Alert: CVE-2026-100851 – AzuraCast

CVE Alert: CVE-2026-100851 – AzuraCast

Redpacketsecurity •admin • September 27, 2026

AzuraCast before 0.23.8 contains a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint that allows authenticated users with only View Station Page permission to read Icecast/Shoutcast admin, source, and relay passwords. Attackers with View-only access can call this endpoint and receive plaintext frontend credentials in the JSON response, then use the admin password to authenticate to the Icecast admin interface without Broadcasting permission.

**Risk verdict:** High risk with a straightforward remote path for a minimally privileged account; exploitation status is unconfirmed because KEV, SSVC, PoC and EPSS data were not supplied.

**Why this matters:** A low-level account could expose credentials that unlock a more privileged streaming administration interface. That could enable unauthorised configuration changes, service disruption or misuse of broadcast infrastructure; broader network compromise is not established by the available scope assessment.

**Most likely attack path:** An attacker first obtains any account with basic station-view access, then makes a network request without needing another user to interact. The flaw has low preconditions and its assessed impact remains within the affected service, though the exposed credentials may allow further actions in its administration interface.

**Who is most exposed:** Internet-accessible self-hosted deployments and shared radio-streaming instances with numerous presenters, volunteers or other limited-access users warrant attention.

Review logs for profile API access by view-only accounts, especially unusual frequency or station coverage.

Inspect responses and application traces for sensitive credential fields; avoid retaining secrets in logs.

Check Icecast/Shoutcast authentication logs for unexpected administrator logins or source/relay changes.

Correlate suspicious API access with subsequent configuration changes or stream interruptions.

Mitigation and prioritisation:

Upgrade promptly to the vendor-fixed release; verify the deployed build rather than relying on package labels.

Until upgraded, restrict access to the application and administration interfaces; remove unnecessary view-only accounts.

Rotate exposed streaming credentials after patching, and review recent administrator activity.

Confirm KEV, SSVC, PoC and EPSS status before final urgency ranking; these indicators are absent here.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities

Platforms (2)