Loading market data...
← Back to CVE feed

CVE-2026-100855

MEDIUM CVSS 6.5 View on NVD ↗

Description

AzuraCast before 0.23.6 contains a missing permission check vulnerability in the GET /api/station/{station_id}/file/{id}/play endpoint that allows authenticated users to download media files from any station. Attackers can enumerate media files using sequential IDs and exfiltrate the complete media library of stations they lack permissions for.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Published: Sep 27, 2026 02:17 UTC Modified: Sep 27, 2026 02:17 UTC