Medium severity5.0NVD Advisory· Published Jan 2, 2026· Updated Jun 17, 2026
CVE-2025-69417
CVE-2025-69417
Description
In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve share tokens (intended for unrelated access) via a shared_servers endpoint.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: 0
cpe:2.3:a:plex:media_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:plex:media_server:*:*:*:*:*:*:*:*range: <=1.43.0.10389
- (no CPE)range: <=2025-12-31
Patches
Vulnerability mechanics
References
1- github.com/lufinkey/vulnerability-research/blob/main/CVE-2025-34158/README.mdnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.