PT-2026-99475 · Azuracast · Azuracast
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
AzuraCast versions prior to 0.23.6
Description
An issue exists where a missing permission check in the 'GET /api/station/{station id}/file/{id}/play' endpoint allows authenticated users to download media files from any station. This can be exploited by enumerating media files using sequential IDs to exfiltrate the complete media library of stations for which the user lacks proper permissions.
Recommendations
Update to version 0.23.6 or later.
Restrict access to the 'GET /api/station/{station id}/file/{id}/play' endpoint to minimize the risk of unauthorized file downloads.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Azuracast