Sceawere

Vulnerability Detail

CVE-2026-100855UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

AzuraCast Unauthorized Media File Access

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
1d ago
Vendor
AzuraCast
Product
AzuraCast
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

AzuraCast before 0.23.6 contains a missing permission check vulnerability in the GET /api/station/{station_id}/file/{id}/play endpoint that allows authenticated users to download media files from any station. Attackers can enumerate media files using sequential IDs and exfiltrate the complete media library of stations they lack permissions for.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-27T02:17:24.893Z",
  "pubdate": "2026-09-27T02:17:24.893Z",
  "executiveSummary": "AzuraCast versions prior to 0.23.6 are susceptible to an Insecure Direct Object Reference (IDOR) vulnerability resulting from a missing permission check on the media file streaming API endpoint.\nThe vulnerability resides within the GET /api/station/{station_id}/file/{id}/play interface, which fails to enforce access control lists (ACLs) to verify that an authenticated user possesses the required privileges for the requested station.\nAn authenticated attacker can leverage this oversight to gain unauthorized access to the media library of any station hosted on the instance, regardless of their assigned permissions.\nBy systematically iterating through sequential {station_id} and {id} parameters, a malicious actor can exfiltrate sensitive audio assets and private content stored within the platform.\nThe risk implication is significant as it facilitates unauthorized data exposure and intellectual property theft.\nSuccessful exploitation requires an existing authenticated session on the AzuraCast platform, but does not necessitate high-level administrative privileges, making it a critical concern for multi-tenant or multi-user environments where isolation between stations is expected.",
  "technicalDetails": "The vulnerability originates from an authorization bypass flaw located in the application's backend controller handling media file playback requests. Specifically, the GET /api/station/{station_id}/file/{id}/play endpoint lacks a server-side authorization check to validate the relationship between the authenticated user session and the target station resource.\nWhen a user sends a GET request to the vulnerable endpoint, the application performs a lookup based on the provided {station_id} and {id} variables. In the affected versions, the controller logic fails to perform an Access Control Check (ACC) to confirm if the requester has the 'view' or 'download' permission for the specific station specified in the URI path.\nBecause the system fails to validate authorization, the application context proceeds to resolve the resource requested by the {id} parameter and serves the file binary directly to the client. This behavior is indicative of a broken object-level authorization (BOLA) pattern.\nAn attacker can automate the exploitation process by utilizing an enumeration technique. Since media files are typically indexed with sequential identifiers, the attacker can script a series of HTTP requests targeting different {station_id} values combined with incrementing {id} values. This allows the attacker to systematically crawl and download the entirety of the station's media repository without restriction.\nThe network exposure is restricted to authenticated users; however, the requirement for authentication is minimal, as it simply necessitates a valid, potentially low-privileged user account. Once authenticated, the attacker effectively circumvents the security boundary intended to isolate station data.\nThe impact of this vulnerability extends beyond simple file access; it allows for bulk exfiltration of digital assets, potentially compromising proprietary content, copyrighted material, or internal station logs stored as media files. Post-exploitation, the attacker has achieved full read-access to the file storage backend for the entire platform, effectively bypassing the platform's multi-tenancy model."
}
CVE-2026-100855: AzuraCast Unauthorized Media File Access (MEDIUM Severity, CVSS: 6.5) | Sceawere