HIGH 8.2 NVD
CVE-2026-100853
In AzuraCast before 0.23.8, the public On-Demand download endpoint fails to verify playlist-level access controls, allowing unauthenticated users to download me
In AzuraCast before 0.23.8, the public On-Demand download endpoint fails to verify playlist-level access controls, allowing unauthenticated users to download media files excluded from On-Demand-enabled playlists. Attackers can bypass the station operator's intended access restrictions by directly requesting media via the download endpoint using valid media identifiers, exposing private or restricted audio content.
References
- https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-q9cc-mp52-vrp9
- https://www.vulncheck.com/advisories/azuracast-before-0.23.8-on-demand-download-endpoint-a
This high severity vulnerability with a CVSS score of 8.2 was published on 2026-09-27 via NVD.
vulnfeed aggregates 11720 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.