Description
AzuraCast before 0.23.6 lacks RequireInternalConnection middleware on the Liquidsoap API endpoint and incorrectly derives the AutoDJ flag from header presence rather than validated value. Users with View station permission can inject arbitrary now-playing metadata, disrupt live broadcasts, and disclose filesystem paths.
Published: 2026-09-27
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Metadata injection and information disclosure via the Liquidsoap API
Action: Immediate Update
AI Analysis

Impact

AzuraCast versions prior to 0.23.6 allow authorized users with View station permissions to send requests to the Liquidsoap API endpoint. Because the endpoint lacks the RequireInternalConnection middleware and wrongfully interprets the presence of an AutoDJ header instead of a validated value, attackers can inject arbitrary now‑playing metadata. This capability enables the manipulation of broadcast content, the disruption of live streams, and the exposure of filesystem paths to the attacker.

Affected Systems

AzuraCast software running any version earlier than 0.23.6 is affected. The vulnerability applies to all deployments where the Liquidsoap API is exposed, regardless of operating system or hosting environment.

Risk and Exploitability

With a CVSS score of 5.3 the vulnerability carries moderate severity. The EPSS score is not available, so the likelihood of exploitation cannot be precisely quantified; however, the vulnerability is not currently listed in the CISA KEV catalog. An attacker requires legitimate credentials with at least View station permissions but can exploit the flaw from any network that can reach the Liquidsoap API, thereby enabling broadcast disruption and sensitive path disclosure.

Generated by OpenCVE AI on September 27, 2026 at 03:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade AzuraCast to version 0.23.6 or later, which implements RequireInternalConnection middleware and corrects AutoDJ flag validation.
  • Restrict exposure of the Liquidsoap API by placing it behind an internal firewall or internal network boundary so that only trusted hosts can reach it.
  • Enforce stricter role‑based access controls so that only privileged users may modify now‑playing metadata, and consider disabling the Liquidsoap API if it is not required in a given environment.

Generated by OpenCVE AI on September 27, 2026 at 03:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Description AzuraCast before 0.23.6 lacks RequireInternalConnection middleware on the Liquidsoap API endpoint and incorrectly derives the AutoDJ flag from header presence rather than validated value. Users with View station permission can inject arbitrary now-playing metadata, disrupt live broadcasts, and disclose filesystem paths.
Title AzuraCast before 0.23.6 Metadata Injection via Liquidsoap API
First Time appeared Azuracast
Azuracast azuracast
Weaknesses CWE-862
CPEs cpe:2.3:a:azuracast:azuracast:*:*:*:*:*:*:*:*
Vendors & Products Azuracast
Azuracast azuracast
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Azuracast Azuracast
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-27T01:28:46.412Z

Reserved: 2026-09-27T00:20:03.854Z

Link: CVE-2026-100854

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-27T02:17:24.747

Modified: 2026-09-27T02:17:24.747

Link: CVE-2026-100854

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T03:45:18Z

Weaknesses