CVE-2026-76836Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission guarding them. The backend_config property in backend/src/Entity/Station.php is annotated with GROUP_GENERAL, and PUT /api/station/{station_id}/profile/edit in backend/src/Controller/Api/Stations/ProfileEditController.php deserializes with that group while requiring only StationPermissions::Profile. AbstractArrayEntity::fromArray() then assigns every public property with no field-level permission check, so custom_config_top, custom_config, custom_config_pre_playlists, custom_config_pre_live, custom_config_pre_fade and custom_config_bottom are writable through it. ConfigWriter::writeCustomConfigurationSection() emits those values verbatim into the generated Liquidsoap .liq script, where the process.run() and process.exec() built-ins execute operating system commands when the backend restarts, which the built-in sync task triggers automatically once needs_restart is set. The dedicated endpoint for the same data, PUT /api/station/{id}/liquidsoap-config, requires StationPermissions::Broadcasting, so a station manager holding only the profile permission reaches configuration that the intended boundary reserves for broadcasting operators.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-24: 3Technical Details · 2026-08-24: 208-24
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-76836 AzuraCast https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-76836

    Post summary

    The text lists CVE-2026-76836 for AzuraCast and provides a URL to a Vulmon vulnerability page, but does not include any details about the vulnerability, any PoC, exploit, or remediation.

    00001138
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-76836 AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission guarding them. The backend_config property in ba… https://www.cve.org/CVERecord?id=CVE-2026-76836 ----- Traducción: CVE-2026-76836 Azu… https://infoflow.cloud`

    Post summary

    The post announces CVE-2026-76836, explaining that an unsecured endpoint exposes Liquidsoap configuration data without proper permission checks. No exploit, patch, or active exploitation details are provided.

    0000028
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-76836 AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission guarding them. The backend_config property in ba… https://www.cve.org/CVERecord?id=CVE-2026-76836

    Post summary

    The post announces that AzuraCast has a new vulnerability (CVE‑2026‑76836) involving unauthorized access to configuration fields, but provides no PoC, exploit details, or patch information.

    000001.1K
    58.0K followersView on X

Explore more