CVE-2025-66723: Inmusicbrands Engine Dj Desktop

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

inMusic Brands Engine DJ before 4.3.4 suffers from Insecure Permissions due to exposed HTTP service in the Remote Library, which allows attackers to access all files and network paths.

Affected products

  • Inmusicbrands Engine Dj Desktop: from 3.0.0, before 4.3.4 (fixed in 4.3.4)

Published 2025-12-30. Last modified 2026-06-17.