CVE-2026-100852
8.8 HIGHpublic exploit availablePublished 2026-09-27 · Updated 2026-09-28
AI risk analysis
- Summary
- This vulnerability allows authenticated users with Streamers and Profile permissions to inject shell commands, leading to potential command execution as the Liquidsoap process user.
- Exploitability
- Exploitation requires the user to have Streamers and Profile permissions and to set a username containing shell metacharacters. The vulnerability is relatively easy to exploit given the required permissions.
- Blast radius
- If exploited, this could lead to full control over the Liquidsoap process, potentially allowing attackers to disrupt the service or execute arbitrary commands.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to AzuraCast 0.23.8 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
AzuraCast before 0.23.8 contains a command injection vulnerability in the Liquidsoap config generation for live recording that fails to quote the streamer username in process.run calls. Authenticated station users with Streamers and Profile permissions can set a username containing shell metacharacters and trigger command execution as the Liquidsoap process user when recording closes.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-78
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-43641
- HIGHCVE-2026-55897PoC
- HIGHCVE-2026-77601PoC
- HIGHCVE-2026-82412PoC
- CRITICALCVE-2026-90822
- HIGHCVE-2025-51457
- CRITICALCVE-2025-66455PoC
- CRITICALCVE-2026-100291
Related by shared AI tags and CWE weakness class. Browse the full archive.