Access Misalignment Vulnerability in Plex Media Server by Plex
CVE-2025-69415

7.1HIGH

Key Information:

Vendor

Plex

Vendor
CVE Published:
2 January 2026

What is CVE-2025-69415?

The Plex Media Server versions up to 1.42.2.10156 exhibit a significant access control flaw that allows unauthorized users to access the /myplex/account endpoint using a device token. This flaw arises due to improper alignment between device token validation and account association, potentially exposing sensitive user account information to attackers. It is crucial for users to assess their security measures and apply the necessary updates to mitigate potential risks.

Affected Version(s)

Media Server 0 <= 1.42.2.10156

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.