---
id: CVE-2026-100847
title: >-
  AzuraCast before 0.23.8 contains a DQL injection vulnerability in the
  sortOrder API parameter of AbstractSearchableListAction.php
summary: >-
  AzuraCast before 0.23.8 contains a DQL injection vulnerability in the
  sortOrder API parameter of AbstractSearchableListAction.php. Attackers can
  inject arbitrary DQL expressions through the sortOrder parameter to extract
  sensitive databa…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-89
vendor: AzuraCast
product: AzuraCast
affected:
  - AzuraCast < 0.23.8
published: '2026-09-27'
updated: '2026-09-27'
sourceUpdated: '2026-09-27T02:17:23.437'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-100847'
references:
  - url: >-
      https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-jqwc-h3rq-frmw
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/azuracast-before-0.23.8-dql-injection-via-sortorder
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-27T02:41:45.575Z'
---

## Overview

AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder API parameter of AbstractSearchableListAction.php. Attackers can inject arbitrary DQL expressions through the sortOrder parameter to extract sensitive database information including user credentials and station settings.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
