CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100847

HIGHCVSS 7.5NVD feed

Published 27 September 2026 · tracked since 27 September 2026

Description

AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder API parameter of AbstractSearchableListAction.php. Attackers can inject arbitrary DQL expressions through the sortOrder parameter to extract sensitive database information including user credentials and station settings.

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-100847 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100847

HIGHCVSS 7.5NVD feed

Published 27 September 2026 · tracked since 27 September 2026

Description

AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder API parameter of AbstractSearchableListAction.php. Attackers can inject arbitrary DQL expressions through the sortOrder parameter to extract sensitive database information including user credentials and station settings.

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]