Security Vulnerability in Plex Media Server Affects User Data
CVE-2025-34158

10CRITICAL

Key Information:

Vendor

Plex

Vendor
CVE Published:
21 August 2025

Badges

📈 Score: 241📰 News Worthy

What is CVE-2025-34158?

CVE-2025-34158 is a security vulnerability affecting the Plex Media Server (PMS), specifically in versions ranging from 1.41.7.x to 1.42.0.x. Plex Media Server is a widely used application that organizes and streams digital media. This vulnerability, reported through Plex’s bug bounty program, has raised concerns regarding the integrity, confidentiality, and availability of user data. Although specific technical details have not been publicly disclosed, its existence indicates a potential risk to the seamless operation of the Plex Media Server and the sensitive information it manages. With the vendor flagging the issue and providing a fix in version 1.42.1, it is critical for users to upgrade to protect their systems from potential threats.

Potential impact of CVE-2025-34158

  1. Risk to Data Integrity: The vulnerability could allow unauthorized alterations to user data, leading to issues with data authenticity and reliability, which could affect user trust and service quality.

  2. Compromise of Confidentiality: Sensitive user data might be at risk of exposure, which could result in privacy violations and compliance issues, particularly for users storing personal or sensitive information.

  3. Degradation of Service Availability: Exploiting this vulnerability could disrupt server operations, rendering the media server inoperable and significantly impacting the user experience for those relying on the service for their media consumption.

Affected Version(s)

Media Server 1.41.7.x < 1.42.1

News Articles

Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws

Plex fixes multiple undisclosed flaws in Media Server 1.43.3 and Desktop 1.115.0, urging users to update.

23 hours ago

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 📰

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

.