Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.7

CVE-2026-100852: AzuraCast lets attacker run commands via streamer name

CVE-2026-100852 · published 13 days ago
Summary

In versions of AzuraCast older than 0.23.8, a station user who can manage streamers can enter a name that includes special characters. When a live recording stops, those characters are treated as commands and are executed on the server with the same rights as the AzuraCast service. Upgrade AzuraCast to version 0.23.8 or later, or restrict who can set streamer names, to stop this risk.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
azuracast azuracast < 0.23.8
<= 0.23.x
Original advisory text
AzuraCast before 0.23.8 Command Injection via Streamer Username
AzuraCast before 0.23.8 contains a command injection vulnerability in the Liquidsoap config generation for live recording that fails to quote the streamer username in process.run calls. Authenticated station users with Streamers and Profile permissions can set a username containing shell metacharacters and trigger command execution as the Liquidsoap process user when recording closes.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
8.7 High
Exploitation
4% chance of attack within 30 days
Type
CWE-78OS Command Injection
Timeline
Published27 Sep 2026
Updated10 Oct 2026
First seen27 Sep 2026
Sources
CVE-2026-100852 · MITRE
Track software like this
Free during beta