Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 27 Sep 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AzuraCast before 0.23.6 contains a code injection vulnerability in the remote relay password field due to incomplete migration from the vulnerable cleanUpString method to toRawString. Attackers with RemoteRelays station permission can inject nested Liquidsoap interpolation syntax to execute arbitrary code in the Liquidsoap process, disclose internal API keys, or disrupt station operation. | |
| Title | AzuraCast before 0.23.6 Code Injection via Remote Relay Password | |
| First Time appeared |
Azuracast
Azuracast azuracast |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:azuracast:azuracast:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Azuracast
Azuracast azuracast |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-27T01:28:47.778Z
Reserved: 2026-09-27T00:20:03.854Z
Link: CVE-2026-100856
No data.
Status : Received
Published: 2026-09-27T02:17:25.050
Modified: 2026-09-27T02:17:25.050
Link: CVE-2026-100856
No data.
OpenCVE Enrichment
Updated: 2026-09-27T05:30:17Z
-
CWE-94
Improper Control of Generation of Code ('Code Injection')