PT-2026-80981 · Azuracast+1 · Azuracast+1

·

CVE-2026-76836

·

Published

2026-08-24

·

Updated

2026-08-24

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AzuraCast (affected versions not specified)
Description An improper permission check in the profile editing process allows users with only profile permissions to modify Liquidsoap custom configuration fields. The endpoint 'PUT /api/station/{station id}/profile/edit' deserializes data using a general group that includes the backend config property, bypassing the stricter permissions required by the dedicated configuration endpoint. This allows the modification of variables including custom config top, custom config, custom config pre playlists, custom config pre live, custom config pre fade, and custom config bottom. These values are written directly into the Liquidsoap .liq script, where the process.run() and process.exec() built-in functions can be used to execute operating system commands upon a backend restart.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76836
GHSA-Q8WG-3QG7-8PC7

Affected Products

Azuracast
Liquidsoap