HIGH
AzuraCast before 0.23.6 Missing Permission Check via /play
Published Sep 27, 2026
7.1
HIGHCVSS 4.0
EPSS 0.21%
Description
AzuraCast before 0.23.6 contains a missing permission check vulnerability in the GET /api/station/{station_id}/file/{id}/play endpoint that allows authenticated users to download media files from any station. Attackers can enumerate media files using sequential IDs and exfiltrate the complete media library of stations they lack permissions for.
Affected products
-
- Version 0StatusaffectedConstraints<0.23.6
- Version 0.23.6StatusunaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87820 Advisory
- https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-qff7-q5fm-8p76 vendor-advisory
- https://www.vulncheck.com/advisories/azuracast-before-0.23.6-missing-permission-check-via-play third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87820 | Advisory | |
| https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-qff7-q5fm-8p76 | vendor-advisory | |
| https://www.vulncheck.com/advisories/azuracast-before-0.23.6-missing-permission-check-via-play | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 27, 2026
Updated Sep 30, 2026
Reserved Sep 27, 2026
Link CVE-2026-100855
CISA Vulnrichment
Updated Sep 30, 2026
ENISA EUVD
EUVD-2026-87820 Assigner VulnCheck
Published Sep 27, 2026
Updated Sep 30, 2026
Exploited since n/a
Link EUVD-2026-87820