Zurück zur CVE-Übersicht
CVE-2026-100851
HIGH(7.6)CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Risk Signal Score29/100 — MITTEL
- CVSS 7.6 — Hoch
- Weniger als 24 Stunden alt
Beschreibung
AzuraCast before 0.23.8 contains a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint that allows authenticated users with only View Station Page permission to read Icecast/Shoutcast admin, source, and relay passwords. Attackers with View-only access can call this endpoint and receive plaintext frontend credentials in the JSON response, then use the admin password to authenticate to the Icecast admin interface without Broadcasting permission.