Sceawere

Vulnerability Detail

CVE-2026-100851UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Broken Access Control in AzuraCast

Vulnerability Metadata

Severity
High
Score / CVSS
7.6
Creation Date
1d ago
Vendor
AzuraCast
Product
AzuraCast
Attack Type
Exposure of Sensitive Information to an Unauthorized Actor
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

AzuraCast before 0.23.8 contains a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint that allows authenticated users with only View Station Page permission to read Icecast/Shoutcast admin, source, and relay passwords. Attackers with View-only access can call this endpoint and receive plaintext frontend credentials in the JSON response, then use the admin password to authenticate to the Icecast admin interface without Broadcasting permission.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.6",
  "pubDate": "2026-09-27T02:17:24.233Z",
  "pubdate": "2026-09-27T02:17:24.233Z",
  "executiveSummary": "AzuraCast versions prior to 0.23.8 are affected by a broken access control vulnerability located within the API layer. The flaw specifically resides in the GET /api/station/{id}/vue/profile endpoint, which incorrectly exposes sensitive configuration data to users with restricted permissions. By design, the endpoint is accessible to authenticated users possessing only 'View Station Page' privileges, yet it returns comprehensive administrative credentials, including Icecast and Shoutcast admin, source, and relay passwords in plaintext.\nThe vulnerability represents a critical security oversight in authorization logic, allowing unauthorized information disclosure. An attacker with minimal view-only access can leverage these credentials to gain administrative control over the underlying radio broadcasting servers, such as the Icecast admin interface, effectively bypassing higher-level authorization requirements like 'Broadcasting' permissions. This exposure facilitates lateral movement and full takeover of the streaming infrastructure, posing a significant risk to the integrity and confidentiality of the affected radio station's backend services.",
  "technicalDetails": "The vulnerability exists due to a failure in the AzuraCast authorization middleware when processing requests to the GET /api/station/{id}/vue/profile endpoint. While the intended design restricts sensitive station management functions to administrative or high-privileged roles, the specified endpoint fails to enforce strict access control lists (ACLs) or parameter filtering during the serialization of the station profile JSON response.\nThe root cause is a deficiency in the API controller logic where the backend retrieves and emits the full station configuration object, including highly sensitive Icecast and Shoutcast administrative credentials, regardless of the requester's actual authorization level. Because the 'View Station Page' permission level provides the necessary authentication to access the station's frontend environment, the API permits the retrieval of this data without conducting a secondary validation check against the user's role-based access control (RBAC) profile.\nThe attack flow follows a predictable pattern: 1) The attacker authenticates to the AzuraCast instance using a low-privileged account possessing only the 'View Station Page' permission. 2) The attacker identifies the target station ID. 3) The attacker submits a GET request to /api/station/{id}/vue/profile. 4) The server processes the request and returns a JSON payload containing the 'admin_password', 'source_password', and 'relay_password' fields in plaintext. 5) The attacker parses these credentials and utilizes them to authenticate directly against the Icecast or Shoutcast management ports, effectively bypassing the intended management constraints imposed by the AzuraCast dashboard.\nThis vulnerability is particularly severe because it allows for privilege escalation in a lateral manner. An attacker does not need to compromise the AzuraCast application itself to impact the underlying broadcast infrastructure, as the exposed credentials provide direct access to the auxiliary server protocols. The exposure includes all relay and source passwords, which could lead to service disruption, credential rotation requirements, or unauthorized broadcast injection if the attacker leverages the source credentials. The lack of input validation or response masking on this specific endpoint ensures that any authenticated user within the scope of the station's view can exfiltrate these secrets without triggering security alerts, provided they have basic read access."
}
CVE-2026-100851: Broken Access Control in AzuraCast (HIGH Severity, CVSS: 7.6) | Sceawere