CVE-2025-69415
Unknown Unknown - Not Provided
Improper Access Control in Plex Media Server Allows Account Exposure

Publication date: 2026-01-02

Last updated on: 2026-02-27

Assigner: MITRE

Description
In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether the device is currently associated with an account.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-01-02
Last Modified
2026-02-27
Generated
2026-06-16
AI Q&A
2026-01-02
EPSS Evaluated
2026-06-14
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
plex media_server to 1.42.2.10156 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-672 The product uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability in Plex Media Server (PMS) through version 1.42.2.10156 allows access to the /myplex/account endpoint using a device token even when the device is not properly associated with an account. This means the access control based on device-account association is not correctly enforced.

Impact Analysis

The vulnerability can lead to unauthorized access to account information or functionality via the /myplex/account endpoint, potentially exposing sensitive user data or allowing limited unauthorized actions. The CVSS score indicates a high impact on confidentiality and some impact on integrity.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-69415. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart