Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 14 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 14 Nov 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sonarr
Sonarr sonarr |
|
| Vendors & Products |
Sonarr
Sonarr sonarr |
Thu, 13 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in Sonarr 4.0.15.2940. The impacted element is an unknown function of the file C:\ProgramData\Sonarr\bin\Sonarr.Console.exe of the component Service. Performing manipulation results in incorrect default permissions. The attack is only possible with local access. The vendor confirms this vulnerability but classifies it as a "low severity issue due to the default service user being used as it would either require someone to intentionally change the service to a highly privileged account or an attacker would need an admin level account". It is planned to fix this issue in the next major release v5. | |
| Title | Sonarr Service Sonarr.Console.exe default permission | |
| Weaknesses | CWE-266 CWE-276 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-11-14T15:58:36.445Z
Reserved: 2025-11-13T15:28:43.342Z
Link: CVE-2025-13131
Updated: 2025-11-14T15:58:32.223Z
Status : Deferred
Published: 2025-11-13T22:15:50.227
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-13131
No data.
OpenCVE Enrichment
Updated: 2025-11-14T09:27:44Z