Token Retrieval Vulnerability in Plex Media Server by Plex
CVE-2025-69417
5MEDIUM
What is CVE-2025-69417?
A vulnerability exists in the Plex Media Server backend that allows a non-server device token to access share tokens through a shared_servers endpoint. This could potentially expose sensitive information intended for unrelated access, thus posing a risk to user privacy and data integrity. Users utilizing Plex service should review their setup and apply necessary security measures to mitigate risks introduced by this vulnerability.
Affected Version(s)
plex.tv backend 0 <= 2025-12-31
