← Back to search

CVE-2026-100852

8.8 HIGHpublic exploit available

Published 2026-09-27 · Updated 2026-09-28

AI risk analysis

Summary
This vulnerability allows authenticated users with Streamers and Profile permissions to inject shell commands, leading to potential command execution as the Liquidsoap process user.
Exploitability
Exploitation requires the user to have Streamers and Profile permissions and to set a username containing shell metacharacters. The vulnerability is relatively easy to exploit given the required permissions.
Blast radius
If exploited, this could lead to full control over the Liquidsoap process, potentially allowing attackers to disrupt the service or execute arbitrary commands.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to AzuraCast 0.23.8 or later.
rceauth-bypassweb

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

AzuraCast before 0.23.8 contains a command injection vulnerability in the Liquidsoap config generation for live recording that fails to quote the streamer username in process.run calls. Authenticated station users with Streamers and Profile permissions can set a username containing shell metacharacters and trigger command execution as the Liquidsoap process user when recording closes.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.