Description
In AzuraCast before 0.23.8, the public On-Demand download endpoint fails to verify playlist-level access controls, allowing unauthenticated users to download media files excluded from On-Demand-enabled playlists. Attackers can bypass the station operator's intended access restrictions by directly requesting media via the download endpoint using valid media identifiers, exposing private or restricted audio content.
Published: 2026-09-27
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Unauthorized download of private audio content due to missing playlist‑level access control
Action: Patch
AI Analysis

Impact

The AzuraCast service, before version 0.23.8, includes a public On‑Demand download endpoint that does not enforce playlist‑level access restrictions. As a result, an unauthenticated user can request media files that are excluded from On‑Demand enabled playlists. The attacker can supply valid media identifiers and retrieve private or restricted audio content that the station operator intended to keep protected. This flaw constitutes a broken access control vulnerability, allowing attackers to obtain data beyond their authorized scope.

Affected Systems

This issue affects the AzuraCast podcasting platform under the vendor AzuraCast. Any installation running a pre‑0.23.8 version is susceptible. The production environment must be identified and verified for the presence of the vulnerable product version.

Risk and Exploitability

The vulnerability has a CVSS score of 8.2, indicating a high severity. The EPSS score is not available, and it is not listed in CISA KEV, suggesting no publicly confirmed exploits at the time of reporting. The likely attack vector is remote, via the publicly reachable download endpoint without authentication. Attackers can exploit the flaw simply by constructing HTTP requests containing valid media identifiers to retrieve restricted files.

Generated by OpenCVE AI on September 27, 2026 at 03:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update AzuraCast to version 0.23.8 or later to eliminate the authorization bypass
  • Restrict access to the On‑Demand download endpoint by requiring authentication or network‑level controls
  • Implement monitoring for unusual download activity to detect potential exploitation attempts

Generated by OpenCVE AI on September 27, 2026 at 03:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Description In AzuraCast before 0.23.8, the public On-Demand download endpoint fails to verify playlist-level access controls, allowing unauthenticated users to download media files excluded from On-Demand-enabled playlists. Attackers can bypass the station operator's intended access restrictions by directly requesting media via the download endpoint using valid media identifiers, exposing private or restricted audio content.
Title AzuraCast before 0.23.8 On-Demand Download Endpoint Authorization Bypass
First Time appeared Azuracast
Azuracast azuracast
Weaknesses CWE-862
CPEs cpe:2.3:a:azuracast:azuracast:*:*:*:*:*:*:*:*
Vendors & Products Azuracast
Azuracast azuracast
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Azuracast Azuracast
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-27T01:28:45.749Z

Reserved: 2026-09-27T00:20:03.854Z

Link: CVE-2026-100853

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-27T02:17:24.590

Modified: 2026-09-27T02:17:24.590

Link: CVE-2026-100853

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T04:15:08Z

Weaknesses