CVE-2020-26948: Emby

Critical severity, CVSS 9.8. EPSS: 87.2% chance of exploitation in the next 30 days.

Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.

Affected products

  • Emby Emby: before 4.5.0 (fixed in 4.5.0)

Published 2020-10-10. Last modified 2026-06-17.