CVE-2021-32833: GHSL-2021-051: Unauthenticated file read in Emby Server - CVE-2021-32833

Published Aug 12, 2021
·
Updated

Emby Server allows unauthenticated file read.

Other sources

Emby Server is a personal media server with apps on many devices. In Emby Server on Windows there is a set of arbitrary file read vulnerabilities. This vulnerability is known to exist in version 4.6.4.0 and may not be patched in later versions. Known vulnerable routes are /Videos/Id/hls/PlaylistId/SegmentId.SegmentContainer, /Images/Ratings/theme/name and /Images/MediaInfo/theme/name. For more details including proof of concept code, refer to the referenced GHSL-2021-051. This issue may lead to unauthorized access to the system especially when Emby Server is configured to be accessible from the Internet.

MITRE

Affected Software

1 affected component
Emby Emby.releases<=4.6.4.0

Event History

Aug 12, 2021
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Sep 9, 2021
CVE Published
via MITRE·01:30 AM
Data Sourced
via MITRE·01:30 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is CVE-2021-32833?

CVE-2021-32833 is an arbitrary file read vulnerability in Emby Server on Windows.

2

What is Emby Server?

Emby Server is a personal media server with apps on many devices.

3

Which version of Emby Server is affected?

Version 4.6.4.0 of Emby Server on Windows is known to be affected.

4

How severe is CVE-2021-32833?

CVE-2021-32833 has a severity rating of 8.6 (high).

5

How can I fix CVE-2021-32833?

There is currently no patch available for CVE-2021-32833, so it is recommended to update to a version of Emby Server that is not vulnerable if possible, and to take necessary precautions to protect your system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203