rootpwn

high · CVSS v3 7.6 · CVSS v4 7.2 · EPSS 0.00207

CVE-2026-100851

AzuraCast versions prior to 0.23.8 expose a broken access control flaw in the /api/station/{id}/vue/profile endpoint. Authenticated users wi

Overview

AzuraCast versions prior to 0.23.8 expose a broken access control flaw in the /api/station/{id}/vue/profile endpoint. Authenticated users with only view permissions can retrieve plaintext Icecast/Shoutcast admin, source, and relay passwords. This allows attackers to gain administrative access to the streaming server.

Description

AzuraCast before 0.23.8 contains a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint that allows authenticated users with only View Station Page permission to read Icecast/Shoutcast admin, source, and relay passwords. Attackers with View-only access can call this endpoint and receive plaintext frontend credentials in the JSON response, then use the admin password to authenticate to the Icecast admin interface without Broadcasting permission.

Impact

Confidentiality: credentials exposed. Integrity: attackers can modify streaming configuration. Availability: potential disruption. Impacted: administrators and operators of AzuraCast deployments with view-only users.

Remediation

Apply the 0.23.8 update or later. If immediate patching is not possible, revoke view-only permissions or block the endpoint via firewall or reverse proxy.

Risk context

High severity but low EPSS (0.00207) indicates a low likelihood of exploitation, yet the impact warrants timely patching.

Affected products

  • AzuraCast 0.23.7 and earlier

Scores

Severity
high
CVSS v2
8
CVSS v3
7.6
CVSS v4
7.2
EPSS
0.00207

AzuraCast AccessControl CredentialExposure Icecast HighSeverity Patch Defender

← All CVEs