cvedb.io
CVE-2025-64113
CRITICAL · CVSS 9.8
EPSS exploitation probability: 0%
Published 2025-12-09T20:15:54.327 · Last modified 2026-06-17T09:53:50.887

Summary

Emby Server is a user-installable home media server. Versions below 4.9.1.81 allow an attacker to gain full administrative access to an Emby Server (for Emby Server administration, not at the OS level). Other than network access, no specific preconditions need to be fulfilled for a server to be vulnerable. This issue is fixed in version 4.9.1.81.

Affected products

emby — emby

Does this affect you?

Add your gear to cvedb and we'll alert you only when emby ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.