Azuracast · Azuracast · CVE-2026-100847
**Name of the Vulnerable Software and Affected Versions**
AzuraCast versions prior to 0.23.8
**Description**
A DQL injection issue exists in the `AbstractSearchableListAction.php` file. An attacker can inject arbitrary DQL (Doctrine Query Language) expressions—an object-oriented query language used by the Doctrine ORM—via the `sortOrder` parameter in the API. This allows for the extraction of sensitive database information, such as station settings and user credentials.
**Recommendations**
Update to version 0.23.8 or later.
As a temporary mitigation, restrict access to the API parameter `sortOrder` within the `AbstractSearchableListAction.php` component.