Security

The Rekordbox and CDJ network flaw: what it is, who is affected, what to do

·

A service that shares files over the network starts by default on affected players, and on computers running Rekordbox once Link Export is on. Anyone else on the same network can reach the files on your USB stick, SD card or drive. This is a real risk at clubs and festivals, where you do not control the network.

If you play on club gear, this one is worth ten minutes of your attention.

On 10 August 2026, AlphaTheta published a security advisory covering Rekordbox and a long list of Pioneer DJ players. The short version: affected devices run a network file-sharing service (NFS) that starts on its own, and it does not properly restrict who may connect. Anyone else on the same network can read the files you have on a USB stick, an SD card, or — if you are running Rekordbox on a laptop with Link Export enabled — on your computer's drive.

What is actually exposed

Not your account. Not your payment details. Your files.

That means the tracks on the stick you just plugged into the player, including promos and unreleased material that was sent to you personally. For a lot of DJs that is the genuinely sensitive part: a promo leaking with your name attached to it is a relationship-ending problem, and it does not require anyone to be a skilled attacker. It requires them to be on the same network as you.

The service starts by default on affected hardware. On the software side it becomes reachable when Link Export mode is enabled — the mode you turn on precisely when you want players to pull tracks from your laptop.

Which gear is on the list

According to the 10 August advisory, the affected hardware includes CDJ-3000 and CDJ-3000X, CDJ-2000NXS2, CDJ-900NXS2, XDJ-1000MK2, XDJ-700, XDJ-RX2 and XDJ-RX3, XDJ-RR, XDJ-XZ, OMNIS-DUO and RMX-IGNITE.

On the software side: Rekordbox v6 and v7 on Windows and macOS, and the Rekordbox mobile apps for iOS and Android.

Listed as not affected: DJM mixers, Stagehand, and PRO DJ LINK Bridge.

If your player is not on that list, do not treat it as proof of safety — treat it as "not named in this advisory". Check the manufacturer's own security page for the current status, because the list and the patch situation both move.

What to do

Update everything, and keep checking. Firmware for the players, and Rekordbox itself. Patches for a list this long do not all land on the same day, so a device you updated in August may have had its fix issued since.

Treat club and festival networks as hostile. Not because the promoter is out to get you, but because you have no idea who else is on that network, and neither does the promoter. This is the practical core of it: the flaw only matters when someone else can reach you.

Turn off what you are not using. If you are playing from a USB stick and not exporting over the network, Link Export does not need to be on. The same goes for the wireless features on the players.

Do not run Rekordbox on open Wi-Fi. The airport, the hotel, the venue's guest network. If you are preparing a set on the road, stay off shared networks while Rekordbox is running.

Lock down the networks you do control. Home and studio Wi-Fi with a strong password, and no guest access to the same segment your gear sits on.

How worried should you be

Proportionately. This is not a remote takeover of your equipment and it is not something a stranger can do from the other side of the internet. It needs network proximity — the same local network you are on.

But "the same local network" describes exactly the environment most DJs work in. A booth on a shared venue network, a green room, a festival compound where every stage is on one link. The people best placed to exploit it are the people standing nearest to you.

The fix is not complicated, which is the good news: update, and stop putting your library on networks you do not control.


One note on where your library lives

We build a key analysis tool, so we will be brief and stay honest about this: nothing above is fixed by using Harmoniq. This is a file-sharing flaw in playback hardware and in library software on your machine; it is a different layer of the problem from where a track gets analysed.

The only related thing worth saying is a design choice we made for our own reasons. Harmoniq analyses audio in your browser, on your machine — there is no server for files to be uploaded to, so there is no copy of your promos anywhere else to worry about. That is an architectural fact about our tool, not a defence against the vulnerability described here, and we are not going to pretend otherwise.

Patch your gear. That is the answer to this one.


Sources: AlphaTheta's security advisory of 10 August 2026, as reported by CDM. Patch availability changes — check the manufacturer's security page for the current state before relying on any list here. This post is updated as the situation develops.

Try it on your own library Runs in your browser. Free to start — no card.

← All posts

© 2026 Harmoniq DJ Terms Privacy Refunds Contact