Emby Server is a user-installable home media server. Versions below 4.9.1.81 allow an attacker to gain full administrative access to an Emby Server (for Emby Server administration, not at the OS level). Other than network access, no specific preconditions need to be fulfilled for a server to be vulnerable. This issue is fixed in version 4.9.1.81.
History

Wed, 10 Dec 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Emby
Emby emby
Vendors & Products Emby
Emby emby

Tue, 09 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 09 Dec 2025 19:30:00 +0000

Type Values Removed Values Added
Description Emby Server is a user-installable home media server. Versions below 4.9.1.81 allow an attacker to gain full administrative access to an Emby Server (for Emby Server administration, not at the OS level). Other than network access, no specific preconditions need to be fulfilled for a server to be vulnerable. This issue is fixed in version 4.9.1.81.
Title Emby Server allows attackers to gain administrative server access without preconditions
Weaknesses CWE-640
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-12-09T20:08:09.863Z

Reserved: 2025-10-27T15:26:14.127Z

Link: CVE-2025-64113

cve-icon Vulnrichment

Updated: 2025-12-09T20:08:06.940Z

cve-icon NVD

Status : Received

Published: 2025-12-09T20:15:54.327

Modified: 2025-12-09T20:15:54.327

Link: CVE-2025-64113

cve-icon Redhat

No data.