PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-100856 AzuraCast CVE debrief

AzuraCast before 0.23.6 contains a code injection vulnerability in the remote relay password field. Attackers with RemoteRelays station permission can inject nested Liquidsoap interpolation syntax to execute arbitrary code in the Liquidsoap process, disclose internal API keys, or disrupt station operation. This vulnerability can lead to significant operational impact, including potential code execution, API key disclosure, and station disruption. Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their systems.

Vendor
AzuraCast
Product
Unknown
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-27
Original CVE updated
2026-10-08
Advisory published
2026-09-27
Advisory updated
2026-10-08

Who should care

Defenders responsible for AzuraCast installations, especially those with RemoteRelays station permissions, should assess exposure and prioritize verification and remediation. This includes reviewing system configurations, monitoring for suspicious activity, and ensuring that the latest version of AzuraCast is installed. Additionally, defenders should consider implementing compensating controls, such as restricting access to sensitive areas of the system,  

Why it matters

Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their systems, especially those with RemoteRelays station permissions, as it can lead to code execution, API key disclosure, and station disruption.

  • Potential code execution in the Liquidsoap process
  • Disclosure of internal API keys
  • Disruption of station operation

Technical summary

The vulnerability exists in the remote relay password field of AzuraCast before 0.23.6. Attackers with RemoteRelays station permission can inject nested Liquidsoap interpolation syntax to execute arbitrary code in the Liquidsoap process, disclose internal API keys, or disrupt station operation. This code injection vulnerability can be exploited through the remote relay password field, allowing attackers to execute arbitrary code in the Liquidsoap process. The vulnerability is due to incomplete migration from the vulnerable cleanUpString method to toRawString.

Defensive priority

Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their systems, especially those with RemoteRelays station permissions.

Recommended defensive actions

  • Verify AzuraCast version and ensure it is 0.23.6 or later
  • Restrict RemoteRelays station permissions to minimize exposure
  • Monitor for suspicious activity in the Liquidsoap process
  • Implement additional logging and monitoring for Liquidsoap process activity
  • Conduct regular security audits to identify potential vulnerabilities
  • Review and update incident response plans to address potential code injection attacks
  • Track and verify patches for AzuraCast and related components

Evidence notes

The CVE record and source item provide details on the vulnerability, including its description, CVSS score, and affected versions. The vulnerability exists in the remote relay password field of AzuraCast before 0.23.6. Attackers with RemoteRelays station permission can inject nested Liquidsoap interpolation syntax to execute arbitrary code in the Liquidsoap process. Evidence is limited to CVE Program and NVD records, which may not cover all affected deployments or variations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-100856 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-100856

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-100856 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100856

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • AzuraCast before 0.23.6 Code Injection via Remote Relay Password

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/100xxx/CVE-2026-100856.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-q4ph-8x8g-95f8

    Supplemental source - vendor-advisory

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/azuracast-before-0.23.6-code-injection-via-remote-relay-password

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.