Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.7
CVE-2026-76836: AzuraCast allows basic users to edit streaming command settings
CVE-2026-76836 · published 1 month ago
Summary
In AzuraCast, users who can only edit a station profile can also change custom Liquidsoap configuration fields, which are written directly into the streaming script and can run system commands. This means an attacker with modest access could cause the server to execute unintended commands when the station restarts. Apply the latest software update and limit profile‑edit rights to trusted staff, or block the affected API endpoint until the fix is deployed.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| azuracast | azuracast | <= 0.23.8 |
Original advisory text
AzuraCast through 0.23.8 Liquidsoap Configuration Write via Profile Edit Serialization Group Bypass
AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission guarding them. The backend_config property in backend/src/Entity/Station.php is annotated with GROUP_GENERAL, and PUT /api/station/{station_id}/profile/edit in backend/src/Controller/Api/Stations/ProfileEditController.php deserializes with that group while requiring only StationPermissions::Profile. AbstractArrayEntity::fromArray() then assigns every public property with no field-level permission check, so custom_config_top, custom_config, custom_config_pre_playlists, custom_config_pre_live, custom_config_pre_fade and custom_config_bottom are writable through it. ConfigWriter::writeCustomConfigurationSection() emits those values verbatim into the generated Liquidsoap .liq script, where the process.run() and process.exec() built-ins execute operating system commands when the backend restarts, which the built-in sync task triggers automatically once needs_restart is set. The dedicated endpoint for the same data, PUT /api/station/{id}/liquidsoap-config, requires StationPermissions::Broadcasting, so a station manager holding only the profile permission reaches configuration that the intended boundary reserves for broadcasting operators.
References
- https://github.com/AzuraCast/AzuraCast
- https://github.com/AzuraCast/AzuraCast/blob/0.23.8/backend/src/Entity/Station.ph...
- https://github.com/AzuraCast/AzuraCast/blob/0.23.8/backend/src/Radio/Backend/Liq...
- https://nvd.nist.gov/vuln/detail/CVE-2026-76836 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76836... Vendor Advisory
- https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-q8wg-3qg7-8pc7
- https://www.vulncheck.com/advisories/azuracast-through-liquidsoap-configuration-...
Severity
8.7
High
CVSS 3.1: 8.8 (NVD)
CVSS 4.0: 8.7 (NVD)
CVSS 4.0: 9.4 (OSV)
Exploitation
EPSS <1%
Type
CWE-94Code Injection
CWE-863Incorrect Authorization
Timeline
Published24 Aug 2026
Updated27 Sep 2026
First seen24 Aug 2026
Track software like this
Free during beta