Junglewise Threat Intelligence

CVE-2026-100854: AzuraCast Liquidsoap API authorization bypass

CVE-2026-100854 · Severity: medium · CVSS 6.3 · Published 2026-09-27

Technologies: AzuraCast. Vendors: AzuraCast.

Executive brief

AzuraCast is a web-based radio station management platform. A flaw in version 0.23.5 and earlier allows users with basic viewing permissions to bypass authentication on the internal Liquidsoap API endpoint, enabling them to inject fake song metadata visible to listeners, disconnect live broadcasts, and disclose server filesystem paths.

Technical details

The vulnerability stems from two flaws: (1) missing RequireInternalConnection middleware on the /api/internal/{station_id}/liquidsoap/{action} endpoint, making it publicly accessible despite being internal-only; (2) the $asAutoDj flag is set based on the presence of the X-Liquidsoap-Api-Key header rather than validation of its value. A user with StationPermissions::View can exploit this over the network to invoke privileged Liquidsoap commands, bypassing authentication checks on FeedbackCommand, DjOffCommand, DjOnCommand, and CopyCommand. Version 0.23.6 patches both issues.

Affected products

  • AzuraCast AzuraCast before 0.23.6

Timeline

  • 2026-09-27: disclosed: Advisory published
  • 2026-04-23: patched: Fix released in version 0.23.6

References

Related threats