CVE-2025-46390
7.5Emby · MediaBrowser
Emby MediaBrowser version 4.9.0.35 contains an observable response discrepancy vulnerability, potentially allowing unauthenticated information disclosure.
Executive summary
A high-severity observable response discrepancy in Emby MediaBrowser exposes the system to unauthenticated information disclosure risks.
Vulnerability
This vulnerability involves an observable response discrepancy (CWE-204), which can allow an unauthenticated remote attacker to gain sensitive information by observing differing server responses.
Business impact
The exploitation of this flaw may lead to unauthorized disclosure of sensitive system information, potentially aiding in further targeted attacks against the infrastructure. With a CVSS score of 7.5, this vulnerability represents a significant risk to data confidentiality and should be addressed with high priority to maintain the integrity of the environment.
Remediation
Immediate Action: Review the official Emby security advisories to identify and apply the latest available security updates or configuration changes.
Proactive Monitoring: Monitor server access logs for anomalous request patterns or high volumes of error-based responses that might indicate an attacker probing for discrepancies.
Compensating Controls: Implement a Web Application Firewall to restrict suspicious traffic patterns and normalize server responses to prevent information leakage.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for unauthenticated information disclosure, organizations utilizing Emby MediaBrowser should prioritize verifying their current version against vendor documentation. Administrators must ensure that security patches are applied as soon as they are made available by the vendor to mitigate the risk of unauthorized data exposure.
Sources
Originally found and disclosed by Moriel Harush, per the CVE Program record.