CVE-2025-64113
Emby Server is a user-installable home media server. Versions below 4.9.1.81 allow an attacker to gain full administrative access to an Emby Server (for Emby Server administration, not at the OS level). Other than network access, no specific preconditions need to be fulfilled for a server to be vulnerable. This issue is fixed in version 4.9.1.81.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
- EPSS probability
- 0.59%
- CWE
- CWE-640
- Published
- 2025-12-09
- Last modified
- 2026-03-12
Affected products
- EmbySupport security
Weakness type
Related vulnerabilities
- CVE-2026-81905 — Concrete CMS below 9.5.3 does not enforce validation-hash type on redemption, allowing a hash issued for one purpose to be redeemed for another.
- CVE-2026-6285 — Improper Authentication in Ankaref's LIBRID/LIBREF
- CVE-2026-86260 — sfturing hosp_order Password Recovery CommonUserController.java modifyPassWord unverified password change
- CVE-2026-84699 — Team Password Manager before 14.184.308 Authentication Bypass in Password Reset
- CVE-2026-82487 — Beetel 450TC3 password recovery
- CVE-2026-19632 — TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
- CVE-2026-80196 — Kimai before 2.58.0 Authentication Bypass via Password Reset Link
- CVE-2026-77264 — Automation Web Platform <= 4.8.6 - Unauthenticated Authentication Bypass via 'otp_transient' Token Disclosure