CVE-2026-100855: AzuraCast before 0.23.6 Missing Permission Check via /play
AzuraCast before 0.23.6 contains a missing permission check vulnerability in the GET /api/station/{stationid}/file/{id}/play endpoint that allows authenticated users to download media files from any station. Attackers can enumerate media files using sequential IDs and exfiltrate the complete media library of stations they lack permissions for.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated AzuraCast user can exploit it. The attacker does not need permission to access the targeted station, but must be able to make requests to the affected API endpoint.
What data can be exposed?
Media files from stations the authenticated user is not authorized to access can be downloaded. Because media file IDs can be enumerated sequentially, an attacker may be able to exfiltrate an affected station's complete media library.
Are default deployments affected?
The vulnerability affects AzuraCast versions before 0.23.6 when authenticated users can access the GET /api/station/{station_id}/file/{id}/play endpoint. The provided information does not identify any additional configuration prerequisite.
How can administrators check for possible exploitation?
Review requests to the affected play endpoint for authenticated users downloading files from station IDs for which they lack permissions. Sequential or broad ranges of file IDs requested across other stations are a strong indicator of enumeration activity.