S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Mar 4, 2025

CVE-2025-27112 Scanner

CVE-2025-27112 Scanner - Authentication Bypass vulnerability in Navidrome

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.1k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-27112
6.9
CVSSmedium
Exploitable remotely over the internet · no authentication required.

Navidrome is an open source web-based music collection server and streamer. Starting in version 0.52.0 and prior to version 0.54.5, in certain Subsonic API endpoints, a flaw in the authentication check process allows an attacker to specify any arbitrary username that does not exist on the system, along with a salted hash of an empty password. Under these conditions, Navidrome treats the request as authenticated, granting access to various Subsonic endpoints without requiring valid credentials. An attacker can use any non-existent username to bypass the authentication system and gain access to various read-only data in Navidrome, such as user playlists. However, any attempt to modify data fails with a "permission denied" error due to insufficient permissions, limiting the impact to unauthorized viewing of information. Version 0.54.5 contains a patch for this issue.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
navidromeby navidrome
>= 0.52.0, < 0.54.5
Updated Aug 22, 2026View on NVD →
Detail

Navidrome is a popular open source web-based music server and streamer, primarily used by music enthusiasts and developers. Its main purpose is to allow users to access and stream their music collections remotely. The software is widely used by individuals and small organizations who want to host their own music streaming service without relying on third-party services. Navidrome is prized for its user-friendly interface, cross-platform compatibility, and robust streaming capabilities. It's particularly popular among users who value open source solutions and self-hosted software for greater control over their data. The software is maintained by an active community and receives regular updates to enhance functionality and security.

The vulnerability detected in Navidrome pertains to an authentication bypass issue within specific Subsonic API endpoints. This flaw allows attackers to bypass the standard authentication mechanisms by using arbitrary usernames alongside a salted hash of an empty password. Consequently, attackers gain unauthorized access to various read-only sections of the Navidrome application. However, due to insufficient permissions, any attempts to alter data are restricted, ensuring the impact remains limited to unauthorized viewing. The vulnerability is critical as it could expose sensitive data to unauthorized users. A patched version, 0.54.5, addresses this security flaw.

The technical details of the authentication bypass vulnerability involve exploiting a loophole in the Subsonic API authentication process. Attackers can specify any non-existent username with a corresponding salted hash for an empty password. When processed, Navidrome erroneously authenticates the request due to the flawed check process. This allows access to various read-only data endpoints, such as user playlists. Despite the successful authentication bypass, modifying data is not possible due to the system's permission controls. This vulnerability primarily affects the confidentiality of user data in Navidrome installations.

If exploited, this authentication bypass vulnerability could lead to several potential effects. Unauthorized users may gain access to view user playlists and other read-only data within Navidrome. While attackers cannot modify data, the exposure of information could lead to privacy breaches or information leaks. This vulnerability may undermine user trust in the application, especially if sensitive information is viewed improperly. Moreover, attackers with knowledge of this flaw could develop automated tools to scan for and exploit vulnerable Navidrome installations. The release of version 0.54.5 is crucial for mitigating these risks.

REFERENCES

Solution Advice
  • Update Navidrome to version 0.54.5 or later to address the authentication bypass vulnerability.
  • Regularly review and audit access logs for unauthorized access attempts.
  • Implement stronger authentication mechanisms, such as two-factor authentication, where possible.
  • Review and update API permissions to ensure data access is appropriately restricted.
  • Educate users and administrators about potential risks and encourage the reporting of suspicious activities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.