PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-100857 AzuraCast CVE debrief

AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media or Profile permissions to inject arbitrary Liquidsoap code into station configuration. This vulnerability can lead to code execution as the azuracast user when the station restarts, potentially causing significant operational impact. Defenders should prioritize verifying and updating AzuraCast installations to version 0.23.4 or later.

Vendor
AzuraCast
Product
Unknown
CVSS
HIGH 8.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-27
Original CVE updated
2026-10-08
Advisory published
2026-09-27
Advisory updated
2026-10-08

Who should care

Defenders responsible for AzuraCast installations, particularly those with Media or Profile permissions, should assess exposure and prioritize verification and remediation. This includes reviewing system configurations, monitoring for suspicious activity, and ensuring that only trusted users have access to Media and Profile permissions. Additionally, defenders should consider the potential operational impacts of this vulnerability, including the potential

Why it matters

CVE-2026-100857 is a high-severity vulnerability in AzuraCast before 0.23.4 that allows authenticated users to inject arbitrary Liquidsoap code, potentially leading to code execution as the azuracast user.

  • Authenticated users with Media or Profile permissions can inject arbitrary Liquidsoap code into station configuration.
  • Injected code can execute shell commands as the azuracast user when the station restarts.
  • Defenders must verify and update AzuraCast installations to version 0.23.4 or later.
  • Remediation priority is high due to the potential for code execution.

Technical summary

The ConfigWriter::cleanUpString() method in AzuraCast before 0.23.4 fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media or Profile permissions to inject arbitrary Liquidsoap code into station configuration. This vulnerability can lead to code execution as the azuracast user when the station restarts. The CVE record and source item provide details on the vulnerability, including its description, affected versions, and references to vendor advisories. Defenders should prioritize verifying and updating AzuraCast installations to version 0.23.4 or later.

Defensive priority

Defenders should prioritize verifying and updating AzuraCast installations to version 0.23.4 or later, and restrict Media and Profile permissions to trusted users.

Recommended defensive actions

  • Verify AzuraCast installations and update to version 0.23.4 or later
  • Restrict Media and Profile permissions to trusted users
  • Monitor station configuration and playlist URLs for suspicious activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide details on the vulnerability, including its description, affected versions, and references to vendor advisories. The ConfigWriter::cleanUpString() method in AzuraCast before 0.23.4 fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media or Profile permissions to inject arbitrary Liquidsoap code into station configuration. Evidence is limited to CVE Program and NVD records, which may not cover all affected deployments or scenarios. Defenders should to

Sources and references

Verified primary and authoritative sources

  • CVE-2026-100857 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-100857

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-100857 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100857

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • AzuraCast before 0.23.4 Remote Code Execution via Liquidsoap string interpolation

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/100xxx/CVE-2026-100857.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-93fx-5qgc-wr38

    Supplemental source - vendor-advisory

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/azuracast-before-0.23.4-remote-code-execution-via-liquidsoap-string-interpolation

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.