Home

Description

Emby Server is a user-installable home media server. Versions below 4.9.1.81 allow an attacker to gain full administrative access to an Emby Server (for Emby Server administration, not at the OS level). Other than network access, no specific preconditions need to be fulfilled for a server to be vulnerable. This issue is fixed in version 4.9.1.81.

PUBLISHED Reserved 2025-10-27 | Published 2025-12-09 | Updated 2025-12-09 | Assigner GitHub_M




CRITICAL: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L

Problem types

CWE-640: Weak Password Recovery Mechanism for Forgotten Password

Product status

< 4.9.1.81
affected

References

github.com/...curity/security/advisories/GHSA-95fv-5gfj-2r84

cve.org (CVE-2025-64113)

nvd.nist.gov (CVE-2025-64113)

Download JSON