In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether the device is currently associated with an account.
Metrics
Affected Vendors & Products
References
History
Fri, 02 Jan 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether the device is currently associated with an account. | |
| Weaknesses | CWE-672 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-01-02T18:00:11.738Z
Reserved: 2026-01-02T16:49:36.542Z
Link: CVE-2025-69415
No data.
Status : Received
Published: 2026-01-02T17:16:23.887
Modified: 2026-01-02T17:16:23.887
Link: CVE-2025-69415
No data.
OpenCVE Enrichment
No data.