CVE-2025-69417: Medium severity Plex Plex Media Server vulnerability
Published Jan 2, 2026
·Updated
In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve share tokens (intended for unrelated access) via a sharedservers endpoint.
Affected Software
2 affected components
Plex Plex Media Server>=1.0.0
Plex Media Server<=1.43.0.10389
Event History
Jan 2, 2026
CVE Published
via MITRE·04:55 PM
Data Sourced
via MITRE·04:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-69417?
CVE-2025-69417 has a high severity rating due to the potential unauthorized access to share tokens.
2
How do I fix CVE-2025-69417?
To mitigate CVE-2025-69417, update your Plex Media Server to the latest version that addresses this vulnerability.
3
What does CVE-2025-69417 affect?
CVE-2025-69417 affects all versions of Plex Media Server starting from version 1.0.0.
4
What is the risk of CVE-2025-69417?
The risk of CVE-2025-69417 lies in a non-server device gaining access to unintended share tokens, potentially leading to unauthorized access.
5
When was CVE-2025-69417 disclosed?
CVE-2025-69417 was disclosed to the public and reported with a deadline of December 31, 2025.