Vendor
high
advisory
CVE-2026-76836 - Improper Access Control in AzuraCast Leads to RCE
2 TTPs 1 CVEAn improper access control vulnerability in AzuraCast allows low-privileged users to inject arbitrary commands into Liquidsoap configurations, leading to remote code execution upon backend restart.
AzuraCast
web-application
rce
access-control
vulnerability
2t
1c
high
advisory
AzuraCast Liquidsoap Code Injection in Remote Relay Password
3 rules 4 TTPsAzuraCast is vulnerable to a Liquidsoap code injection vulnerability due to the incomplete migration from `cleanUpString()` to `toRawString()` in the remote relay password field, allowing a user with the `RemoteRelays` station permission to inject arbitrary Liquidsoap code by exploiting nested interpolation syntax, leading to arbitrary code execution, API key disclosure, and station disruption.
AzuraCast
code-injection
liquidsoap
ghsa
3r
4t