CVE-2025-69415
Unknown Unknown - Not Provided
Improper Access Control in Plex Media Server Allows Account Exposure

Publication date: 2026-01-02

Last updated on: 2026-02-27

Assigner: MITRE

Description
In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether the device is currently associated with an account.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-01-02
Last Modified
2026-02-27
Generated
2026-05-07
AI Q&A
2026-01-02
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
plex media_server to 1.42.2.10156 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-672 The product uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.
Attack-Flow Graph
AI Powered Q&A
How can this vulnerability impact me? :

The vulnerability can lead to unauthorized access to account information or functionality via the /myplex/account endpoint, potentially exposing sensitive user data or allowing limited unauthorized actions. The CVSS score indicates a high impact on confidentiality and some impact on integrity.


Can you explain this vulnerability to me?

This vulnerability in Plex Media Server (PMS) through version 1.42.2.10156 allows access to the /myplex/account endpoint using a device token even when the device is not properly associated with an account. This means the access control based on device-account association is not correctly enforced.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart