PT-2026-1109 · Plex · Plex Media Server
CVE-2025-69415
·
Publicado
2026-01-02
·
Atualizado
2026-02-27
CVSS v3.1
7.1
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Plex Media Server versions prior to 1.42.2.10157
Description
Plex Media Server (PMS) has an issue where access to the
/myplex/account endpoint with a device token is not correctly linked to the device's account association status. This could allow unauthorized access.Recommendations
Update Plex Media Server to version 1.42.2.10157 or later.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Plex Media Server