{"id":"CVE-2026-100851","published":"2026-09-27T02:17:24.233","lastModified":"2026-09-28T20:51:05.473","description":"AzuraCast before 0.23.8 contains a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint that allows authenticated users with only View Station Page permission to read Icecast/Shoutcast admin, source, and relay passwords. Attackers with View-only access can call this endpoint and receive plaintext frontend credentials in the JSON response, then use the admin password to authenticate to the Icecast admin interface without Broadcasting permission.","cvssScore":7.6,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L","cwes":["CWE-200"],"vendors":[],"products":[],"references":[{"url":"https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-qwh6-x463-ccf4","tags":[]},{"url":"https://www.vulncheck.com/advisories/azuracast-before-0.23.8-broken-access-control-via-get-api-station-id-vue-profile","tags":[]}],"exploitRefs":[{"url":"https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-qwh6-x463-ccf4","tags":[]}],"hasPoc":true,"ai":null}