OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100857

HIGH · CVSS 8 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-27 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

AzuraCast versions prior to 0.23.4 are vulnerable to a code injection flaw that allows authenticated users with Media or Profile permissions to inject arbitrary Liquidsoap code into station configurations. This vulnerability can lead to the execution of shell commands as the azuracast user, particularly through manipulated playlist URLs or metadata fields upon station restart. Organizations using AzuraCast should prioritize patching to mitigate the risk of unauthorized command execution.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100857
Severity
HIGH
CVSS
8
EPSS
0.34%

Original NVD Description

AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media or Profile permissions to inject arbitrary Liquidsoap code into station configuration. Attackers can inject #{process.run()} expressions into playlist URLs or station metadata fields that execute shell commands as the azuracast user when the station restarts.