Home
HIGH: 8.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:NDefault status
unknown
Any version
affected
Description
Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access token.
Problem types
CWE-863 Incorrect Authorization
Product status
Any version
References
github.com/...ty-research/blob/main/CVE-2025-34158/README.md
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.