Access Misalignment Vulnerability in Plex Media Server by Plex
CVE-2025-69415
7.1HIGH
What is CVE-2025-69415?
The Plex Media Server versions up to 1.42.2.10156 exhibit a significant access control flaw that allows unauthorized users to access the /myplex/account endpoint using a device token. This flaw arises due to improper alignment between device token validation and account association, potentially exposing sensitive user account information to attackers. It is crucial for users to assess their security measures and apply the necessary updates to mitigate potential risks.
Affected Version(s)
Media Server 0 <= 1.42.2.10156
