high · CVSS v3 7.6 · CVSS v4 7.2 · EPSS 0.00207
CVE-2026-100851
AzuraCast versions prior to 0.23.8 expose a broken access control flaw in the /api/station/{id}/vue/profile endpoint. Authenticated users wi
Overview
AzuraCast versions prior to 0.23.8 expose a broken access control flaw in the /api/station/{id}/vue/profile endpoint. Authenticated users with only view permissions can retrieve plaintext Icecast/Shoutcast admin, source, and relay passwords. This allows attackers to gain administrative access to the streaming server.
Description
AzuraCast before 0.23.8 contains a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint that allows authenticated users with only View Station Page permission to read Icecast/Shoutcast admin, source, and relay passwords. Attackers with View-only access can call this endpoint and receive plaintext frontend credentials in the JSON response, then use the admin password to authenticate to the Icecast admin interface without Broadcasting permission.
Impact
Confidentiality: credentials exposed. Integrity: attackers can modify streaming configuration. Availability: potential disruption. Impacted: administrators and operators of AzuraCast deployments with view-only users.
Remediation
Apply the 0.23.8 update or later. If immediate patching is not possible, revoke view-only permissions or block the endpoint via firewall or reverse proxy.
Risk context
High severity but low EPSS (0.00207) indicates a low likelihood of exploitation, yet the impact warrants timely patching.
Affected products
- AzuraCast 0.23.7 and earlier
Scores
- Severity
- high
- CVSS v2
- 8
- CVSS v3
- 7.6
- CVSS v4
- 7.2
- EPSS
- 0.00207