high · CVSS v3 5.9 · CVSS v4 8.2 · EPSS 0.00242
CVE-2026-100853
In AzuraCast before 0.23.8, the public On-Demand download endpoint fails to verify playlist-level access controls, allow…
Description
In AzuraCast before 0.23.8, the public On-Demand download endpoint fails to verify playlist-level access controls, allowing unauthenticated users to download media files excluded from On-Demand-enabled playlists. Attackers can bypass the station operator's intended access restrictions by directly requesting media via the download endpoint using valid media identifiers, exposing private or restricted audio content.
Scores
- Severity
- high
- CVSS v2
- 5.4
- CVSS v3
- 5.9
- CVSS v4
- 8.2
- EPSS
- 0.00242