Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 27 Sep 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In AzuraCast before 0.23.8, the public On-Demand download endpoint fails to verify playlist-level access controls, allowing unauthenticated users to download media files excluded from On-Demand-enabled playlists. Attackers can bypass the station operator's intended access restrictions by directly requesting media via the download endpoint using valid media identifiers, exposing private or restricted audio content. | |
| Title | AzuraCast before 0.23.8 On-Demand Download Endpoint Authorization Bypass | |
| First Time appeared |
Azuracast
Azuracast azuracast |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:azuracast:azuracast:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Azuracast
Azuracast azuracast |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-28T13:25:48.092Z
Reserved: 2026-09-27T00:20:03.854Z
Link: CVE-2026-100853
Updated: 2026-09-28T13:20:04.958Z
Status : Deferred
Published: 2026-09-27T02:17:24.590
Modified: 2026-09-28T21:02:16.150
Link: CVE-2026-100853
No data.
OpenCVE Enrichment
Updated: 2026-09-27T04:15:08Z
-
CWE-862
Missing Authorization