CVE-2026-100856: AzuraCast before 0.23.6 Code Injection via Remote Relay Password
AzuraCast before 0.23.6 contains a code injection vulnerability in the remote relay password field due to incomplete migration from the vulnerable cleanUpString method to toRawString. Attackers with RemoteRelays station permission can inject nested Liquidsoap interpolation syntax to execute arbitrary code in the Liquidsoap process, disclose internal API keys, or disrupt station operation.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs an account or other access with the RemoteRelays station permission. It is not described as exploitable by an unauthenticated user.
What capabilities could successful exploitation provide?
An attacker can inject nested Liquidsoap interpolation syntax and execute arbitrary code in the Liquidsoap process. The issue may also allow disclosure of internal API keys or disruption of station operation.
Which deployments are affected?
AzuraCast versions before 0.23.6 are affected. The vulnerable input is the remote relay password field.
How can I determine whether I may be exposed?
Check whether the AzuraCast version is earlier than 0.23.6 and identify accounts or roles granted the RemoteRelays station permission. Systems where untrusted users hold that permission are exposed to exploitation through remote relay password changes.