CVE-2025-69416: Medium severity Plex Plex Media Server vulnerability
Published Jan 2, 2026
·Updated
In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve other tokens (intended for unrelated access) via clients.plex.tv/devices.xml.
Affected Software
2 affected components
Plex Plex Media Server<=2025-12-31
Plex Media Server<=1.43.0.10389
Event History
Jan 2, 2026
CVE Published
via MITRE·04:52 PM
Data Sourced
via MITRE·04:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-69416?
CVE-2025-69416 is considered a high-severity vulnerability due to unauthorized token retrieval.
2
How do I fix CVE-2025-69416?
To fix CVE-2025-69416, ensure that you upgrade your Plex Media Server to the latest version released after December 31, 2025.
3
What type of devices are affected by CVE-2025-69416?
CVE-2025-69416 affects non-server devices that can access the Plex Media Server backend.
4
How does CVE-2025-69416 impact user data security?
CVE-2025-69416 allows unauthorized access to sensitive device tokens, potentially compromising user data security.
5
Is there a workaround for CVE-2025-69416?
Currently, there are no reliable workarounds for CVE-2025-69416 other than upgrading to a patched version of Plex Media Server.