Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.6
CVE-2026-100857: AzuraCast lets logged-in users execute commands on restart
CVE-2026-100857 · published 13 days ago
Summary
If you run AzuraCast version earlier than 0.23.4, a user who can edit media or profile settings can add special code that runs system commands when the station restarts. This could let an attacker make the server do things like install software or read data. Update AzuraCast to version 0.23.4 or later to stop the risk.
What to do
- Update azuracast azuracast to version 0.23.4 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| azuracast | azuracast | < 0.23.4 |
Original advisory text
AzuraCast before 0.23.4 Remote Code Execution via Liquidsoap string interpolation
AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media or Profile permissions to inject arbitrary Liquidsoap code into station configuration. Attackers can inject #{process.run()} expressions into playlist URLs or station metadata fields that execute shell commands as the azuracast user when the station restarts.
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
8.6
High
Type
CWE-94Code Injection
Timeline
Published27 Sep 2026
Updated9 Oct 2026
First seen27 Sep 2026
Track software like this
Free during beta