CVE-2025-69414: High severity Plex Plex Media Server vulnerability
Published Jan 2, 2026
·Updated
Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access token.
Affected Software
2 affected components
Plex Plex Media Server<=1.42.2.10156
Plex Media Server<=1.42.2.10156
Event History
Jan 2, 2026
CVE Published
via MITRE·04:43 PM
Data Sourced
via MITRE·04:43 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-69414?
CVE-2025-69414 is classified with high severity due to its potential to expose sensitive access tokens.
2
How do I fix CVE-2025-69414?
To mitigate CVE-2025-69414, update your Plex Media Server to the latest version beyond 1.42.2.10156.
3
What versions of Plex Media Server are affected by CVE-2025-69414?
Plex Media Server versions up to and including 1.42.2.10156 are affected by CVE-2025-69414.
4
What is the impact of CVE-2025-69414?
The impact of CVE-2025-69414 allows unauthorized retrieval of permanent access tokens, leading to potential account compromise.
5
Is there a workaround for CVE-2025-69414?
Currently, there are no official workarounds for CVE-2025-69414 other than upgrading to a secure version.