PatchSiren cyber security CVE debrief
CVE-2026-100857 AzuraCast CVE debrief
AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media or Profile permissions to inject arbitrary Liquidsoap code into station configuration. This vulnerability can lead to code execution as the azuracast user when the station restarts, potentially causing significant operational impact. Defenders should prioritize verifying and updating AzuraCast installations to version 0.23.4 or later.
- Vendor
- AzuraCast
- Product
- Unknown
- CVSS
- HIGH 8.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-27
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-09-27
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for AzuraCast installations, particularly those with Media or Profile permissions, should assess exposure and prioritize verification and remediation. This includes reviewing system configurations, monitoring for suspicious activity, and ensuring that only trusted users have access to Media and Profile permissions. Additionally, defenders should consider the potential operational impacts of this vulnerability, including the potential
Why it matters
CVE-2026-100857 is a high-severity vulnerability in AzuraCast before 0.23.4 that allows authenticated users to inject arbitrary Liquidsoap code, potentially leading to code execution as the azuracast user.
- Authenticated users with Media or Profile permissions can inject arbitrary Liquidsoap code into station configuration.
- Injected code can execute shell commands as the azuracast user when the station restarts.
- Defenders must verify and update AzuraCast installations to version 0.23.4 or later.
- Remediation priority is high due to the potential for code execution.
Technical summary
The ConfigWriter::cleanUpString() method in AzuraCast before 0.23.4 fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media or Profile permissions to inject arbitrary Liquidsoap code into station configuration. This vulnerability can lead to code execution as the azuracast user when the station restarts. The CVE record and source item provide details on the vulnerability, including its description, affected versions, and references to vendor advisories. Defenders should prioritize verifying and updating AzuraCast installations to version 0.23.4 or later.
Defensive priority
Defenders should prioritize verifying and updating AzuraCast installations to version 0.23.4 or later, and restrict Media and Profile permissions to trusted users.
Recommended defensive actions
- Verify AzuraCast installations and update to version 0.23.4 or later
- Restrict Media and Profile permissions to trusted users
- Monitor station configuration and playlist URLs for suspicious activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the vulnerability, including its description, affected versions, and references to vendor advisories. The ConfigWriter::cleanUpString() method in AzuraCast before 0.23.4 fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media or Profile permissions to inject arbitrary Liquidsoap code into station configuration. Evidence is limited to CVE Program and NVD records, which may not cover all affected deployments or scenarios. Defenders should to
Sources and references
Verified primary and authoritative sources
-
CVE-2026-100857 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-100857
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-100857 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100857
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
AzuraCast before 0.23.4 Remote Code Execution via Liquidsoap string interpolation
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/100xxx/CVE-2026-100857.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-93fx-5qgc-wr38
Supplemental source - vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/azuracast-before-0.23.4-remote-code-execution-via-liquidsoap-string-interpolation
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.