Sceawere
Vulnerability Detail
CVE-2026-100854UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
AzuraCast Liquidsoap API Authentication Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 1d ago
- Vendor
- AzuraCast
- Product
- AzuraCast
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
AzuraCast before 0.23.6 lacks RequireInternalConnection middleware on the Liquidsoap API endpoint and incorrectly derives the AutoDJ flag from header presence rather than validated value. Users with View station permission can inject arbitrary now-playing metadata, disrupt live broadcasts, and disclose filesystem paths.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-09-27T02:17:24.747Z",
"pubdate": "2026-09-27T02:17:24.747Z",
"executiveSummary": "AzuraCast versions prior to 0.23.6 are susceptible to an improper authorization vulnerability within the Liquidsoap API endpoint. The core issue stems from the absence of the RequireInternalConnection middleware and flawed logic in validating the AutoDJ flag.\nThis vulnerability allows an attacker with 'View station' permissions—a relatively low-privilege role—to bypass intended access controls. By exploiting this oversight, an authenticated user can interact with the Liquidsoap API directly, bypassing restrictions that should be limited to internal system processes.\nThe successful exploitation of this flaw enables an attacker to manipulate live broadcast streams, inject arbitrary now-playing metadata, and conduct information disclosure attacks to identify filesystem paths. The vulnerability poses significant risks to broadcast integrity and platform security, as it transitions a low-privileged user into a position capable of disrupting service operations and performing unauthorized administrative-level interactions with the station's streaming backend.",
"technicalDetails": "The vulnerability resides in the Liquidsoap API endpoint implementation within AzuraCast. The security architecture fails to enforce the RequireInternalConnection middleware, which is designed to ensure that specific sensitive endpoints are only accessible by the internal system or trusted processes, rather than directly by web-authenticated users. Consequently, the endpoint becomes reachable by users possessing standard 'View station' permissions, significantly expanding the attack surface.\nThe root cause is twofold: the omission of architectural access control middleware and a failure in data validation logic regarding the AutoDJ flag. Specifically, the application incorrectly derives the AutoDJ status by merely checking for the presence of a header rather than validating the content or context of the header value itself. This trust-based approach allows an attacker to craft forged requests that mimic legitimate internal communication, effectively spoofing the AutoDJ signal.\nThe exploitation flow typically follows these steps: 1) An attacker authenticates to the AzuraCast web interface with 'View station' privileges. 2) The attacker identifies the Liquidsoap API endpoint, which lacks the expected RequireInternalConnection enforcement. 3) The attacker constructs a malicious HTTP request targeting this endpoint, injecting arbitrary metadata into the now-playing stream. 4) By manipulating the AutoDJ flag logic, the attacker induces the application to process the request as a legitimate system command, allowing them to override broadcast stream states. 5) Through further probing of the API responses, the attacker can solicit verbose error messages or state reports that leak internal filesystem paths, aiding in reconnaissance for further system compromise.\nThe impact is critical regarding broadcast security. An attacker can force the system to display incorrect metadata, which may be used for social engineering or reputation damage, or disrupt live broadcasts by forcing state changes in the AutoDJ. Furthermore, the disclosure of filesystem paths provides an attacker with valuable intelligence regarding the server’s underlying directory structure, which can be leveraged to refine additional exploits against the host environment. Because the vulnerability exists in the API handling logic, it is accessible as long as the web interface is exposed to the user, necessitating an immediate update to version 0.23.6 or later."
}