---
id: CVE-2026-100851
title: >-
  AzuraCast before 0.23.8 contains a broken access control vulnerability in the
  GET /api/station/{id}/vue/profile endpoint that allows authenticated users
  with only View Station Page permission to read Icecast/Shoutcast admin,
  source, and …
summary: >-
  AzuraCast before 0.23.8 contains a broken access control vulnerability in the
  GET /api/station/{id}/vue/profile endpoint that allows authenticated users
  with only View Station Page permission to read Icecast/Shoutcast admin,
  source, and …
severity: high
cvss: 7.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L'
cwe:
  - CWE-200
vendor: AzuraCast
product: AzuraCast
affected:
  - AzuraCast < 0.23.8
published: '2026-09-27'
updated: '2026-09-27'
sourceUpdated: '2026-09-27T02:17:24.233'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-100851'
references:
  - url: >-
      https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-qwh6-x463-ccf4
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/azuracast-before-0.23.8-broken-access-control-via-get-api-station-id-vue-profile
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-27T02:41:45.577Z'
---

## Overview

AzuraCast before 0.23.8 contains a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint that allows authenticated users with only View Station Page permission to read Icecast/Shoutcast admin, source, and relay passwords. Attackers with View-only access can call this endpoint and receive plaintext frontend credentials in the JSON response, then use the admin password to authenticate to the Icecast admin interface without Broadcasting permission.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
