---
id: CVE-2026-100853
title: >-
  In AzuraCast before 0.23.8, the public On-Demand download endpoint fails to
  verify playlist-level access controls, allowing unauthenticated users to
  download media files excluded from On-Demand-enabled playlists
summary: >-
  In AzuraCast before 0.23.8, the public On-Demand download endpoint fails to
  verify playlist-level access controls, allowing unauthenticated users to
  download media files excluded from On-Demand-enabled playlists. Attackers can
  bypass the…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-862
vendor: AzuraCast
product: AzuraCast
affected:
  - AzuraCast < 0.23.8
published: '2026-09-27'
updated: '2026-09-27'
sourceUpdated: '2026-09-27T02:17:24.590'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-100853'
references:
  - url: >-
      https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-q9cc-mp52-vrp9
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/azuracast-before-0.23.8-on-demand-download-endpoint-authorization-bypass
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-27T02:41:45.578Z'
---

## Overview

In AzuraCast before 0.23.8, the public On-Demand download endpoint fails to verify playlist-level access controls, allowing unauthenticated users to download media files excluded from On-Demand-enabled playlists. Attackers can bypass the station operator's intended access restrictions by directly requesting media via the download endpoint using valid media identifiers, exposing private or restricted audio content.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
