Impact
The AzuraCast service, before version 0.23.8, includes a public On‑Demand download endpoint that does not enforce playlist‑level access restrictions. As a result, an unauthenticated user can request media files that are excluded from On‑Demand enabled playlists. The attacker can supply valid media identifiers and retrieve private or restricted audio content that the station operator intended to keep protected. This flaw constitutes a broken access control vulnerability, allowing attackers to obtain data beyond their authorized scope.
Affected Systems
This issue affects the AzuraCast podcasting platform under the vendor AzuraCast. Any installation running a pre‑0.23.8 version is susceptible. The production environment must be identified and verified for the presence of the vulnerable product version.
Risk and Exploitability
The vulnerability has a CVSS score of 8.2, indicating a high severity. The EPSS score is not available, and it is not listed in CISA KEV, suggesting no publicly confirmed exploits at the time of reporting. The likely attack vector is remote, via the publicly reachable download endpoint without authentication. Attackers can exploit the flaw simply by constructing HTTP requests containing valid media identifiers to retrieve restricted files.
OpenCVE Enrichment