CVE-2025-46390

7.5

Emby · MediaBrowser

Emby MediaBrowser version 4.9.0.35 contains an observable response discrepancy vulnerability, potentially allowing unauthenticated information disclosure.

Executive summary

A high-severity observable response discrepancy in Emby MediaBrowser exposes the system to unauthenticated information disclosure risks.

Vulnerability

This vulnerability involves an observable response discrepancy (CWE-204), which can allow an unauthenticated remote attacker to gain sensitive information by observing differing server responses.

Business impact

The exploitation of this flaw may lead to unauthorized disclosure of sensitive system information, potentially aiding in further targeted attacks against the infrastructure. With a CVSS score of 7.5, this vulnerability represents a significant risk to data confidentiality and should be addressed with high priority to maintain the integrity of the environment.

Remediation

Immediate Action: Review the official Emby security advisories to identify and apply the latest available security updates or configuration changes.

Proactive Monitoring: Monitor server access logs for anomalous request patterns or high volumes of error-based responses that might indicate an attacker probing for discrepancies.

Compensating Controls: Implement a Web Application Firewall to restrict suspicious traffic patterns and normalize server responses to prevent information leakage.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the potential for unauthenticated information disclosure, organizations utilizing Emby MediaBrowser should prioritize verifying their current version against vendor documentation. Administrators must ensure that security patches are applied as soon as they are made available by the vendor to mitigate the risk of unauthorized data exposure.

Sources

Originally found and disclosed by Moriel Harush, per the CVE Program record.