GHSA-6mwx-gw6f-5f36HighCVSS 7.6

AzuraCast before 0.23.8 contains a broken access control vulnerability in the GET /api/station/...

Published
September 27, 2026
Last Modified
September 27, 2026

🔗 CVE IDs covered (1)

📋 Description

AzuraCast before 0.23.8 contains a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint that allows authenticated users with only View Station Page permission to read Icecast/Shoutcast admin, source, and relay passwords. Attackers with View-only access can call this endpoint and receive plaintext frontend credentials in the JSON response, then use the admin password to authenticate to the Icecast admin interface without Broadcasting permission.

🔗 References (4)