CVE Vulnerabilities

CVE-2025-69415

Operation on a Resource after Expiration or Release

Published: Jan 02, 2026 | Modified: Feb 27, 2026
CVSS 3.x
7.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether the device is currently associated with an account.

Weakness

The product uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.

Affected Software

NameVendorStart VersionEnd Version
Media_serverPlex*1.42.2.10156 (including)

References