CVE-2025-69415

🟡 Monitoruj

Błąd w Plex Media Server umożliwia dostęp do konta bez odpowiedniego powiązania urządzenia.

CVSS
7.1
EPSS
0.3%
Exploit
poc
Vendor
plex
Opis źródłowy (NVD)

In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether the device is currently associated with an account.

exploit Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.1
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2026-01-02 17:16:23 UTC
Ostatnia modyfikacja (NVD)2026-09-30 23:10:00 UTC
Referencje