Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-67917: zuraCast Backup Restore SQL Injection Risk
CVE-2026-67917 · published 17 days ago
Summary
Old zuraCast versions have a security risk in their backup restore feature. If not updated, an attacker could gain more access to your system. Update to a safe version of zuraCast to fix this issue.
Original advisory text
zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality. The `azuracast:restore` command executes the `db.sql` file extracted from a b...
zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality. The `azuracast:restore` command executes the `db.sql` file extracted from a backup archive without any content validation or sanitization. This allows a remote attacker to escalate privileges
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-89SQL Injection
Timeline
Published17 Aug 2026
Updated3 Sep 2026
First seen17 Aug 2026
Monitor software like this
Free during beta