PULSE
FEED
ransomm3rx reclama a cipher.systems · US · Technologyransombarracuda reclama a International Chemical Co. · Manufacturingransompayoutsking reclama a M****n · US · Not Foundransomstorm reclama a Applied Composites · US · Manufacturingransomstorm reclama a Magna Legal Services · US · Professional Servicesransomthegentlemen reclama a Ligue se Grupo · PT · Otherransomthegentlemen reclama a Charles Keith · SG · Retail & E-Commerceransomthegentlemen reclama a ENKEI******* · Manufacturingransomthegentlemen reclama a FTAPI Software · US · Technologyransomtermite reclama a Crossett · US · Otherransomsilentransomgroup reclama a N... · Not Foundransomsilentransomgroup reclama a S... · Not Foundransommetaencryptor reclama a GE Vernova Inc. · US · Energy & Utilitiesransommetaencryptor reclama a PKF Hadiwinata · ID · Professional Servicesransomm3rx reclama a cipher.systems · US · Technologyransombarracuda reclama a International Chemical Co. · Manufacturingransompayoutsking reclama a M****n · US · Not Foundransomstorm reclama a Applied Composites · US · Manufacturingransomstorm reclama a Magna Legal Services · US · Professional Servicesransomthegentlemen reclama a Ligue se Grupo · PT · Otherransomthegentlemen reclama a Charles Keith · SG · Retail & E-Commerceransomthegentlemen reclama a ENKEI******* · Manufacturingransomthegentlemen reclama a FTAPI Software · US · Technologyransomtermite reclama a Crossett · US · Otherransomsilentransomgroup reclama a N... · Not Foundransomsilentransomgroup reclama a S... · Not Foundransommetaencryptor reclama a GE Vernova Inc. · US · Energy & Utilitiesransommetaencryptor reclama a PKF Hadiwinata · ID · Professional Services
← Todos los CVEs
CVE Watch27 sept 2026

CVE-2026-100855

AzuraCast before 0.23.6 contains a missing permission check vulnerability in the GET /api/station/{station_id}/file/{id}/play endpoint that

CVSS

6.5

Medio

EPSS

—

KEV

—

Exploit Today

—

0-100

Publicado: 27 sept 2026 · Última mod.: 27 sept 2026 · CWE-862

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

AzuraCast before 0.23.6 contains a missing permission check vulnerability in the GET /api/station/{station_id}/file/{id}/play endpoint that allows authenticated users to download media files from any station. Attackers can enumerate media files using sequential IDs and exfiltrate the complete media library of stations they lack permissions for.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-1008546.3 MED
—
———AzuraCast before 0.23.6 lacks RequireInternalConnection middleware on the Liquidsoap API endpoint and incorrectly derives the AutoDJ flag from header presence rather than validated value. Users with View station permission can inject arbitrary now-playing metadata, disrupt live broadcasts, and disclose filesystem paths.10h
CVE-2026-1008535.9 MED
—
———In AzuraCast before 0.23.8, the public On-Demand download endpoint fails to verify playlist-level access controls, allowing unauthenticated users to download media files excluded from On-Demand-enabled playlists. Attackers can bypass the station operator's intended access restrictions by directly requesting media via the download endpoint using valid media identifiers, exposing private or restricted audio content.10h
CVE-2026-1007447.3 ALT
—
———A flaw has been found in coollabsio Coolify up to 4.1.2. The affected element is an unknown function of the file app/Http/Middleware/CanUpdateResource.php of the component Route-Level Middleware. Executing a manipulation can lead to missing authorization. The attack may be launched remotely. The exploit has been published and may be used. Upgrading to version 4.2.0 is sufficient to fix this issue. This patch is called 39ae16de4248075de8c08f3259114e064b20d52d. It is advisable to upgrade the affected component.10h
CVE-2026-785826.5 MED
—
——0Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding Synthetics privileges scoped to a single Kibana space could permanently delete Synthetics monitors that are shared into spaces they have no access to. Where a monitor is associated with a private location, the same operation also destroys the underlying Elastic Agent integration configuration without the authorization checks that Fleet would otherwise apply.13h
CVE-2026-1006344.7 MED
—
——0SiYuan before v3.8.4 does not validate the sender or restrict recipients in the 'siyuan-send-windows' IPC handler of the Electron main process (app/electron/main.js). The handler ignores event.sender and forwards any received payload to every BrowserWindow returned by BrowserWindow.getAllWindows(), including windows belonging to other opened workspaces. A renderer connected to an attacker-controlled remote kernel can therefore send {cmd: "lockscreenByMode"} and have it delivered across the workspace boundary; a sibling workspace window whose lockScreenMode is set to 1 invokes lockScreen(). Repeated messages allow the remote workspace to repeatedly lock unrelated local workspace windows, causing a limited denial of service. No confidentiality, integrity, or code-execution impact was observed.22h
CVE-2026-1006178.8 ALT
—
——0Cap-go capgo.app fails to validate that principals in channel_permission_overrides belong to the organization, allowing authenticated app/org admins to grant channel permissions to non-member users. Attackers with admin privileges can insert override rows with arbitrary external user UUIDs to grant channel-scoped permissions such as channel.promote_bundle to users outside the organization.22h