Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 27 Sep 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AzuraCast before 0.23.8 contains a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint that allows authenticated users with only View Station Page permission to read Icecast/Shoutcast admin, source, and relay passwords. Attackers with View-only access can call this endpoint and receive plaintext frontend credentials in the JSON response, then use the admin password to authenticate to the Icecast admin interface without Broadcasting permission. | |
| Title | AzuraCast before 0.23.8 Broken Access Control via GET /api/station/{id}/vue/profile | |
| First Time appeared |
Azuracast
Azuracast azuracast |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:azuracast:azuracast:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Azuracast
Azuracast azuracast |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-27T01:28:44.349Z
Reserved: 2026-09-27T00:18:40.972Z
Link: CVE-2026-100851
No data.
Status : Received
Published: 2026-09-27T02:17:24.233
Modified: 2026-09-27T02:17:24.233
Link: CVE-2026-100851
No data.
OpenCVE Enrichment
Updated: 2026-09-27T04:00:17Z
-
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor