rootpwn

high · CVSS v3 5.9 · CVSS v4 8.2 · EPSS 0.00242

CVE-2026-100853

In AzuraCast before 0.23.8, the public On-Demand download endpoint fails to verify playlist-level access controls, allow…

Description

In AzuraCast before 0.23.8, the public On-Demand download endpoint fails to verify playlist-level access controls, allowing unauthenticated users to download media files excluded from On-Demand-enabled playlists. Attackers can bypass the station operator's intended access restrictions by directly requesting media via the download endpoint using valid media identifiers, exposing private or restricted audio content.

Scores

Severity
high
CVSS v2
5.4
CVSS v3
5.9
CVSS v4
8.2
EPSS
0.00242

← All CVEs