logo

Critical Emby Server Vulnerability Let Attackers Gain Admin Access

ID: f28551fe-836e-59f3-a36a-b073046cf0a3

STIX ID: report--f28551fe-836e-59f3-a36a-b073046cf0a3

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2025-12-09

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical unauthenticated password-recovery vulnerability (CVE-2025-64113, CVSS v4 9.3) in Emby Server allows attackers to gain full administrative access to affected stable and beta releases (up to 4.9.1.80 and 4.9.2.6); Emby has released patches (stable 4.9.1.90, beta 4.9.2.7) and recommends immediate updates or temporarily restricting access to the passwordreset.txt file as a workaround.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.