PatchSiren cyber security CVE debrief
CVE-2026-100856 AzuraCast CVE debrief
AzuraCast before 0.23.6 contains a code injection vulnerability in the remote relay password field. Attackers with RemoteRelays station permission can inject nested Liquidsoap interpolation syntax to execute arbitrary code in the Liquidsoap process, disclose internal API keys, or disrupt station operation. This vulnerability can lead to significant operational impact, including potential code execution, API key disclosure, and station disruption. Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their systems.
- Vendor
- AzuraCast
- Product
- Unknown
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-27
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-09-27
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for AzuraCast installations, especially those with RemoteRelays station permissions, should assess exposure and prioritize verification and remediation. This includes reviewing system configurations, monitoring for suspicious activity, and ensuring that the latest version of AzuraCast is installed. Additionally, defenders should consider implementing compensating controls, such as restricting access to sensitive areas of the system,
Why it matters
Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their systems, especially those with RemoteRelays station permissions, as it can lead to code execution, API key disclosure, and station disruption.
- Potential code execution in the Liquidsoap process
- Disclosure of internal API keys
- Disruption of station operation
Technical summary
The vulnerability exists in the remote relay password field of AzuraCast before 0.23.6. Attackers with RemoteRelays station permission can inject nested Liquidsoap interpolation syntax to execute arbitrary code in the Liquidsoap process, disclose internal API keys, or disrupt station operation. This code injection vulnerability can be exploited through the remote relay password field, allowing attackers to execute arbitrary code in the Liquidsoap process. The vulnerability is due to incomplete migration from the vulnerable cleanUpString method to toRawString.
Defensive priority
Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their systems, especially those with RemoteRelays station permissions.
Recommended defensive actions
- Verify AzuraCast version and ensure it is 0.23.6 or later
- Restrict RemoteRelays station permissions to minimize exposure
- Monitor for suspicious activity in the Liquidsoap process
- Implement additional logging and monitoring for Liquidsoap process activity
- Conduct regular security audits to identify potential vulnerabilities
- Review and update incident response plans to address potential code injection attacks
- Track and verify patches for AzuraCast and related components
Evidence notes
The CVE record and source item provide details on the vulnerability, including its description, CVSS score, and affected versions. The vulnerability exists in the remote relay password field of AzuraCast before 0.23.6. Attackers with RemoteRelays station permission can inject nested Liquidsoap interpolation syntax to execute arbitrary code in the Liquidsoap process. Evidence is limited to CVE Program and NVD records, which may not cover all affected deployments or variations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-100856 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-100856
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-100856 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100856
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
AzuraCast before 0.23.6 Code Injection via Remote Relay Password
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/100xxx/CVE-2026-100856.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-q4ph-8x8g-95f8
Supplemental source - vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/azuracast-before-0.23.6-code-injection-via-remote-relay-password
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.