Plex Media Server Vulnerability Allows Access Token Retrieval by Lufinkey
CVE-2025-69414

8.5HIGH

Key Information:

Vendor

Plex

Vendor
CVE Published:
2 January 2026

What is CVE-2025-69414?

A vulnerability in Plex Media Server versions up to 1.42.2.10156 allows attackers to retrieve a permanent access token through a malicious call to the /myplex/account endpoint, using a transient access token. This weakness can lead to unauthorized access to user accounts and sensitive data, potentially compromising the privacy and security of users.

Affected Version(s)

Media Server 0 <= 1.42.2.10156

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.