CVE-2025-34158: Plex Media Server (PMS) 1.41.7.x - 1.42.0.x Unspecified Vulnerabiliity
Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/account provides the credentials of the server owner (and a /api/resources call reveals other servers accessible by that server owner).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34158?
The severity of CVE-2025-34158 has not been explicitly detailed, but it is acknowledged as a security vulnerability affecting specific versions of Plex Media Server.
How do I fix CVE-2025-34158?
To fix CVE-2025-34158, upgrade your Plex Media Server to version 1.42.1 or later.
Which versions of Plex Media Server are affected by CVE-2025-34158?
Plex Media Server versions 1.41.7.x through 1.42.0.x are affected by CVE-2025-34158.
Has CVE-2025-34158 been publicly disclosed?
Technical details regarding CVE-2025-34158 have not been publicly disclosed.
Is there a workaround for CVE-2025-34158?
There is no specific workaround mentioned for CVE-2025-34158; updating to the latest version is recommended.