Record summary

CVE-2020-26948 has a selected CVSS score of 9.8 (critical); EIP currently links 2 catalogued exploits and 1 Nuclei template.

Description

Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 18, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
2
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

2

Catalogued exploits

MetasploitEmby SSRF HTTP ScannerMetasploit auxiliary PoCby BtnzNot analyzed1 file

Ruby

Metasploit

PoC details
MetasploitEmby Version ScannerMetasploit auxiliary PoCby BtnzNot analyzed1 file

Ruby

Metasploit

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALEmby < 4.5.0 - Server Server-Side Request ForgeryCVSS 9.8

Emby Server before 4.5.0 allows server-side request forgery (SSRF) via the Items/RemoteSearch/Image ImageURL parameter.

Impact

An attacker can exploit this vulnerability to access internal resources, perform port scanning, and potentially pivot to other systems.

Remediation

Apply the latest security patches or upgrade to a patched version of Emby Server.

WeaknessesCWE-918
Authorsdwisiswant0
Template tagscve2020cveembyjellyfinssrfvulnvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:emby:emby:*:*:*:*:*:*:*:*
Shodan: http.title:"emby"
FOFA: title="emby"
Google: intitle:"emby"

Source: ProjectDiscovery

References

3