CVE-2025-46386

8.8

Emby · MediaBrowser

Emby MediaBrowser version 4.9.0.35 is susceptible to an authorization bypass vulnerability caused by user controlled keys, allowing authenticated users to access unauthorized resources.

Executive summary

A critical authorization bypass flaw in Emby MediaBrowser version 4.9.0.35 enables authenticated users to gain unauthorized access to sensitive data or functions.

Vulnerability

The software is vulnerable to CWE-639, an authorization bypass through user controlled keys. The CVSS vector (PR:L) confirms that an attacker must possess a valid, low-privileged user account to trigger the flaw.

Business impact

This vulnerability poses a significant risk to the confidentiality and integrity of the media environment. With a CVSS score of 8.8, the ability for a low-privileged user to bypass authorization controls could lead to unauthorized data access, modification of system configurations, or potential lateral movement within the application.

Remediation

Immediate Action: Administrators should monitor official security advisories from Emby for the release of a patched version and apply the update as soon as it becomes available.

Proactive Monitoring: Review application access logs for unusual patterns, such as users accessing resources outside of their assigned scope or frequent unauthorized access attempts.

Compensating Controls: Implement strict network segmentation and ensure that the media server is not exposed to the public internet without additional layers of authentication, such as a secure VPN or an identity-aware proxy.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the high CVSS score, this vulnerability represents a severe risk to organizational security. Security teams should prioritize identifying instances of the affected version and prepare for immediate deployment of the vendor patch once it is released to prevent potential exploitation.

Sources

Originally found and disclosed by Moriel Harush, per the CVE Program record.