Medium severity5.0NVD Advisory· Published Jan 2, 2026· Updated Jun 17, 2026
CVE-2025-69416
CVE-2025-69416
Description
In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve other tokens (intended for unrelated access) via clients.plex.tv/devices.xml.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: 0
<=2025-12-31+ 1 more
- (no CPE)range: <=2025-12-31
- cpe:2.3:a:plex:media_server:*:*:*:*:*:*:*:*range: <=1.43.0.10389
Patches
Vulnerability mechanics
References
1- github.com/lufinkey/vulnerability-research/blob/main/CVE-2025-34158/README.mdnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.