Sceawere
Vulnerability Detail
CVE-2026-100853UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
AzuraCast Broken Access Control Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.9
- Creation Date
- 1d ago
- Vendor
- AzuraCast
- Product
- AzuraCast
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
In AzuraCast before 0.23.8, the public On-Demand download endpoint fails to verify playlist-level access controls, allowing unauthenticated users to download media files excluded from On-Demand-enabled playlists. Attackers can bypass the station operator's intended access restrictions by directly requesting media via the download endpoint using valid media identifiers, exposing private or restricted audio content.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.9",
"pubDate": "2026-09-27T02:17:24.590Z",
"pubdate": "2026-09-27T02:17:24.590Z",
"executiveSummary": "This vulnerability is classified as an Improper Authorization flaw, specifically categorized as Broken Access Control, affecting the AzuraCast platform prior to version 0.23.8.\nThe issue resides within the public On-Demand download endpoint, which fails to enforce established playlist-level access controls.\nAn unauthenticated remote attacker can exploit this weakness to bypass intended security policies set by station operators, enabling the unauthorized retrieval of restricted or private media files.\nThe primary risk implication is the unauthorized disclosure of sensitive audio content that was specifically excluded from On-Demand availability.\nNo authentication or elevated privileges are required to conduct this attack, as the endpoint incorrectly exposes files to any user capable of supplying a valid media identifier.\nThe vulnerability allows for potential mass data exfiltration of media assets if the attacker can enumerate valid media IDs, posing a significant risk to content confidentiality and intellectual property rights within the AzuraCast environment.",
"technicalDetails": "The vulnerability originates from a deficiency in the access control logic within the AzuraCast On-Demand download component. Specifically, the application's backend fails to perform secondary validation checks against the requested media resource when processed through the download endpoint.\nWhile the system correctly implements logic to exclude specific media from authorized On-Demand playlists, the download endpoint does not verify if a requested file is explicitly associated with an 'On-Demand-enabled' playlist or if the caller possesses the necessary permissions to access the specific asset.\nThe exploitation flow involves an attacker directly interacting with the public download API endpoint. Because the endpoint trustfully accepts media identifiers without verifying the underlying object's access restrictions, the application defaults to serving the file regardless of its restricted status.\nAttackers can leverage this by programmatically requesting valid media identifiers, which may be discovered through enumeration or side-channel information leakage. Upon receiving a valid identifier, the application processes the request, locates the file on the server's storage, and serves it as an HTTP response.\nThe root cause is a failure to implement a 'deny-by-default' security posture within the function responsible for serving media downloads. Instead of validating that the requested media object belongs to a public-facing playlist prior to stream initiation, the service assumes that knowledge of the identifier constitutes sufficient authorization.\nThis constitutes a critical security failure in multi-tenant environments where operators rely on AzuraCast's UI-based controls to segregate private content from public-facing On-Demand libraries. The lack of an authorization layer at the controller level effectively renders the playlist-level restriction settings unenforceable for the specific download endpoint.\nAffected versions include all iterations of AzuraCast preceding version 0.23.8. The vulnerability is present in any instance where the public download feature is enabled, resulting in an unrestricted read access to the media filesystem for any network-reachable entity.\nThe post-exploitation impact includes the full unauthorized disclosure of private radio content, potentially leading to copyright infringement, exposure of pre-release media, or the leakage of sensitive internal communications stored within the media management system."
}