CVE-2025-69415: High severity Plex Plex Media Server vulnerability
Published Jan 2, 2026
·Updated
In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether the device is currently associated with an account.
Affected Software
2 affected components
Plex Plex Media Server<=1.42.2.10156
Plex Media Server<=1.42.2.10156
Event History
Jan 2, 2026
CVE Published
via MITRE·04:49 PM
Data Sourced
via MITRE·04:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-69415?
CVE-2025-69415 is rated as a moderate vulnerability due to improper access control for the /myplex/account endpoint.
2
How do I fix CVE-2025-69415?
To mitigate CVE-2025-69415, update Plex Media Server to the latest version beyond 1.42.2.10156.
3
What does CVE-2025-69415 affect?
CVE-2025-69415 affects Plex Media Server versions up to and including 1.42.2.10156.
4
What are the consequences of CVE-2025-69415?
If exploited, CVE-2025-69415 could allow unauthorized access to user account information associated with the device token.
5
How can I determine if my system is vulnerable to CVE-2025-69415?
Check your Plex Media Server version; if it is 1.42.2.10156 or lower, your system is vulnerable to CVE-2025-69415.