CVE-2026-76836: AzuraCast through 0.23.8 Liquidsoap Configuration Write via Profile Edit Serialization Group Bypass
AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission guarding them. The backendconfig property in backend/src/Entity/Station.php is annotated with GROUPGENERAL, and PUT /api/station/{stationid}/profile/edit in backend/src/Controller/Api/Stations/ProfileEditController.php deserializes with that group while requiring only StationPermissions::Profile. AbstractArrayEntity::fromArray() then assigns every public property with no field-level permission check, so customconfigtop, customconfig, customconfigpreplaylists, customconfigprelive, customconfigprefade and customconfigbottom are writable through it. ConfigWriter::writeCustomConfigurationSection() emits those values verbatim into the generated Liquidsoap .liq script, where the process.run() and process.exec() built-ins execute operating system commands when the backend restarts, which the built-in sync task triggers automatically once needsrestart is set. The dedicated endpoint for the same data, PUT /api/station/{id}/liquidsoap-config, requires StationPermissions::Broadcasting, so a station manager holding only the profile permission reaches configuration that the intended boundary reserves for broadcasting operators.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AzuraCast (Liquidsoap Configuration Write via Profile Edit Serialization Group Bypass)to a version that resolves this vulnerability.Fixed in 0.23.8 - Compensating control
Use the dedicated Liquidsoap configuration endpoint authorization boundary (PUT /api/station/{id}/liquidsoap-config requiring StationPermissions::Broadcasting) so that users with only StationPermissions::Profile cannot write Liquidsoap custom configuration fields.
Event History
Frequently Asked Questions
Which users can exploit this issue?
A station manager with only the StationPermissions::Profile permission can exploit it. They do not need the StationPermissions::Broadcasting permission that is required by the dedicated Liquidsoap configuration endpoint.
What is required for command execution after modifying the configuration?
The attacker can write Liquidsoap custom configuration fields through the station profile edit endpoint and include Liquidsoap process.run() or process.exec() calls. Setting the configuration marks the backend as needing restart, and the built-in sync task automatically triggers the restart that causes the generated script to execute.