No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 30 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 27 Sep 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AzuraCast before 0.23.8 contains a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint that allows authenticated users with only View Station Page permission to read Icecast/Shoutcast admin, source, and relay passwords. Attackers with View-only access can call this endpoint and receive plaintext frontend credentials in the JSON response, then use the admin password to authenticate to the Icecast admin interface without Broadcasting permission. | |
| Title | AzuraCast before 0.23.8 Broken Access Control via GET /api/station/{id}/vue/profile | |
| First Time appeared |
Azuracast
Azuracast azuracast |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:azuracast:azuracast:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Azuracast
Azuracast azuracast |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-30T15:20:33.536Z
Reserved: 2026-09-27T00:18:40.972Z
Link: CVE-2026-100851
Updated: 2026-09-30T15:20:28.767Z
Status : Deferred
Published: 2026-09-27T02:17:24.233
Modified: 2026-09-30T16:17:03.000
Link: CVE-2026-100851
No data.
OpenCVE Enrichment
Updated: 2026-09-27T06:45:17Z