CVE-2026-100855: AzuraCast before 0.23.6 Missing Permission Check via /play

Published Sep 27, 2026
·
Updated

AzuraCast before 0.23.6 contains a missing permission check vulnerability in the GET /api/station/{stationid}/file/{id}/play endpoint that allows authenticated users to download media files from any station. Attackers can enumerate media files using sequential IDs and exfiltrate the complete media library of stations they lack permissions for.

Affected Software

1 affected component
azuracast azuracast<0.23.6

Event History

Sep 27, 2026
CVE Published
via MITRE·01:28 AM
Data Sourced
via MITRE·01:28 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated AzuraCast user can exploit it. The attacker does not need permission to access the targeted station, but must be able to make requests to the affected API endpoint.

2

What data can be exposed?

Media files from stations the authenticated user is not authorized to access can be downloaded. Because media file IDs can be enumerated sequentially, an attacker may be able to exfiltrate an affected station's complete media library.

3

Are default deployments affected?

The vulnerability affects AzuraCast versions before 0.23.6 when authenticated users can access the GET /api/station/{station_id}/file/{id}/play endpoint. The provided information does not identify any additional configuration prerequisite.

4

How can administrators check for possible exploitation?

Review requests to the affected play endpoint for authenticated users downloading files from station IDs for which they lack permissions. Sequential or broad ranges of file IDs requested across other stations are a strong indicator of enumeration activity.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203