# Information related to security Vulnerabilities

**URL:** <https://forums.plex.tv/t/information-related-to-security-vulnerabilities/935164>\
**Category:** Plex Media Server\
**Tags:** server-linux\
**Created:** [January 5, 2026, 10:03am UTC](https://forums.plex.tv/t/information-related-to-security-vulnerabilities/935164 "2026-01-05T10:03:51Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![math4706](https://avatars.discourse-cdn.com/v4/letter/m/f05b48/32.png) [@math4706](https://forums.plex.tv/u/math4706)\
**Post date:** [January 5, 2026, 10:03am UTC](https://forums.plex.tv/t/information-related-to-security-vulnerabilities/935164/1 "2026-01-05T10:03:51Z")

</div>

Server Version#: 4.147.1  
Player Version#:

German news site mentioned that there are still open vulnerabilites in plex media server, [CVE-2025-69414](https://nvd.nist.gov/vuln/detail/CVE-2025-69414), [CVE-2025-69415](https://nvd.nist.gov/vuln/detail/CVE-2025-69415) and also in the [plex.tv](http://plex.tv) backend ([CVE-2025-69416](https://nvd.nist.gov/vuln/detail/CVE-2025-69416), [CVE-2025-69417](https://nvd.nist.gov/vuln/detail/CVE-2025-69417)). Link to the news site: [Plex Media Server: Noch ungepatchte Zugriffsschwachstellen | heise online](https://www.heise.de/news/Plex-Media-Server-Noch-ungepatchte-Zugriffsschwachstellen-11128582.html).

I couldn’t find any information regarding these CVEs here in the forum and would like to know the current status of the mitigations.

Thanks!

Mathes

---

<div class="post-metadata">

**Author:** ![tom80H](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/tom80h/32/19753_2.png) [@tom80H](https://forums.plex.tv/u/tom80H)\
**Post date:** [January 5, 2026, 12:53pm UTC](https://forums.plex.tv/t/information-related-to-security-vulnerabilities/935164/3 "2026-01-05T12:53:10Z")

</div>

> [@math4706](#):
>
> …there are **still** open vulnerabilites

While the article claims this is vulnerabilities from „shortly after the security announcement in August 2025“… the CVEs were only raised / first received by NIST last Friday. Makes me wonder…

---

<div class="post-metadata">

**Author:** ![Kilgry](https://avatars.discourse-cdn.com/v4/letter/k/73ab20/32.png) [@Kilgry](https://forums.plex.tv/u/Kilgry)\
**Post date:** [January 5, 2026, 10:07pm UTC](https://forums.plex.tv/t/information-related-to-security-vulnerabilities/935164/4 "2026-01-05T22:07:19Z")

</div>

Does Plex, inc. have any information? Are these known issues, new or fixed?

---

<div class="post-metadata">

**Author:** ![Lazarus\_Long](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/lazarus_long/32/333009_2.png) [@Lazarus\_Long](https://forums.plex.tv/u/Lazarus_Long)\
**Post date:** [January 5, 2026, 10:57pm UTC](https://forums.plex.tv/t/information-related-to-security-vulnerabilities/935164/5 "2026-01-05T22:57:45Z")

</div>

Plex better get on top of this with a general statement as to whether the vulnerabilities indicated have already been addressed or not!

---

<div class="post-metadata">

**Author:** ![Kilgry](https://avatars.discourse-cdn.com/v4/letter/k/73ab20/32.png) [@Kilgry](https://forums.plex.tv/u/Kilgry)\
**Post date:** [January 6, 2026, 3:44pm UTC](https://forums.plex.tv/t/information-related-to-security-vulnerabilities/935164/6 "2026-01-06T15:44:48Z")

</div>

No news is good news?

---

<div class="post-metadata">

**Author:** ![Lazarus\_Long](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/lazarus_long/32/333009_2.png) [@Lazarus\_Long](https://forums.plex.tv/u/Lazarus_Long)\
**Post date:** [January 6, 2026, 3:55pm UTC](https://forums.plex.tv/t/information-related-to-security-vulnerabilities/935164/7 "2026-01-06T15:55:58Z")

</div>

Hello Plex team, can someone provide an update?!

I would think these types of posts should rise to the top of whoever monitors these forums!

---

<div class="post-metadata">

**Author:** ![J0E](https://avatars.discourse-cdn.com/v4/letter/j/ecd19e/32.png) [@J0E](https://forums.plex.tv/u/J0E)\
**Post date:** [January 6, 2026, 5:56pm UTC](https://forums.plex.tv/t/information-related-to-security-vulnerabilities/935164/8 "2026-01-06T17:56:29Z")

</div>

I just scanned the plexinc/pms-docker:latest and linuxserver/plex:latest docker image and neither show that vulnerability. You can scan it yourself, too, to double check.

sudo docker run --rm -v /var/run/docker.sock:/var/run/docker.sock aquasec/trivy image --severity LOW,MEDIUM,HIGH,CRITICAL --format table linuxserver/plex:latest

sudo docker run --rm -v /var/run/docker.sock:/var/run/docker.sock aquasec/trivy image --severity LOW,MEDIUM,HIGH,CRITICAL --format table plexinc/pms-docker:latest

---

<div class="post-metadata">

**Author:** ![no\_usernames\_left](https://avatars.discourse-cdn.com/v4/letter/n/b4bc9f/32.png) [@no\_usernames\_left](https://forums.plex.tv/u/no_usernames_left)\
**Post date:** [January 6, 2026, 5:58pm UTC](https://forums.plex.tv/t/information-related-to-security-vulnerabilities/935164/9 "2026-01-06T17:58:15Z")

</div>

> **[NVD - CVE-2025-69414](https://nvd.nist.gov/vuln/detail/CVE-2025-69414)**

---

<div class="post-metadata">

**Author:** ![no\_usernames\_left](https://avatars.discourse-cdn.com/v4/letter/n/b4bc9f/32.png) [@no\_usernames\_left](https://forums.plex.tv/u/no_usernames_left)\
**Post date:** [January 6, 2026, 6:06pm UTC](https://forums.plex.tv/t/information-related-to-security-vulnerabilities/935164/11 "2026-01-06T18:06:21Z")

</div>

As someone whose full-time career is in security, reading the notes about the unpatched token management vulns is _wild_ (and not just that they still remain unpatched). How are transient tokens being exchanged for permanent tokens? How are device tokens irrevocable? So many questions.

**tl;dr: lmao so I guess I’m gonna sell my Lifetime Plex Pass and switch to an alternative media server (yes that one).**

> <https://github.com/lufinkey/vulnerability-research/blob/main/CVE-2025-34158/README.md>

---

<div class="post-metadata">

**Author:** ![Kilgry](https://avatars.discourse-cdn.com/v4/letter/k/73ab20/32.png) [@Kilgry](https://forums.plex.tv/u/Kilgry)\
**Post date:** [January 7, 2026, 3:18am UTC](https://forums.plex.tv/t/information-related-to-security-vulnerabilities/935164/13 "2026-01-07T03:18:27Z")

</div>

I’m hoping this silence means Plex is scrambling to get patches in place ASAP and then release PR.

---

<div class="post-metadata">

**Author:** ![OttoKerner](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/ottokerner/32/10079_2.png) [@OttoKerner](https://forums.plex.tv/u/OttoKerner)\
**Post date:** [January 7, 2026, 9:05am UTC](https://forums.plex.tv/t/information-related-to-security-vulnerabilities/935164/14 "2026-01-07T09:05:14Z")

</div>

The majority of these issues has been fixed for quite a while.

The only remaining thing is the `/myplex/account` endpoint. Let me remind you that in order to exploit that one, you need to have a valid access token in the first place – i.e. you need to be a legitimate user of that server.  
It is currently being investigated if that endpoint can be removed altogether.  
But first it needs to be clarified if it’s still being used by some client.

---

<div class="post-metadata">

**Author:** ![math4706](https://avatars.discourse-cdn.com/v4/letter/m/f05b48/32.png) [@math4706](https://forums.plex.tv/u/math4706)\
**Post date:** [January 12, 2026, 4:14pm UTC](https://forums.plex.tv/t/information-related-to-security-vulnerabilities/935164/15 "2026-01-12T16:14:08Z")

</div>

Thanks for the clarification that someone is looking in the remaining issues! Is there any update when this will be finished?

Thanks!

Mathes

---

<div class="post-metadata">

**Author:** ![njeri123](https://avatars.discourse-cdn.com/v4/letter/n/b5ac83/32.png) [@njeri123](https://forums.plex.tv/u/njeri123)\
**Post date:** [January 15, 2026, 2:23am UTC](https://forums.plex.tv/t/information-related-to-security-vulnerabilities/935164/16 "2026-01-15T02:23:12Z")

</div>

Even if **CVE-2025-69414** requires an existing transient token, **[plex.tv](http://plex.tv) backend authorization flaws** mean tokens may be **retrievable or mis-scoped via backend APIs**. In particular **CVE-2025-69416** (device token can enumerate unrelated tokens via `clients.plex.tv/devices.xml`) and **CVE-2025-69417** (share token leakage via `shared_servers`) indicate **server-side authorization bypasses** , not purely local issues.

Can you confirm whether these **[plex.tv](http://plex.tv) API authorization paths** are now fixed in production and whether **token enumeration and share-token access** are fully constrained?

---

<div class="post-metadata">

**Author:** ![hsousa](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/hsousa/32/246565_2.png) [@hsousa](https://forums.plex.tv/u/hsousa)\
**Post date:** [January 15, 2026, 9:25am UTC](https://forums.plex.tv/t/information-related-to-security-vulnerabilities/935164/17 "2026-01-15T09:25:40Z")

</div>

Hi!

We have an issue open to stop both endpoints from returning tokens, now that we have verified that no instance of PMS or a Plex client is using them anymore. It should be patched in production soon.

That being said, let me also add that while returning tokens in these endpoints is bad practice (which is why we’re patching them), to retrieve such tokens you need to already be authenticated with a non-transient token yourself, that has similar (if not more elevated) credentials as provided by the other ones.

For example, getting tokens from `shared_servers` requires you to have a token associated with the server’s admin account. If you have that, you already have the keys to the castle. If you hit the endpoint on a server you’re not the admin of, you get _ **nothing** _.

Sure, you can get _different_ tokens, but if an attacker can hit those endpoints then the system was already compromised elsewhere.

I’m not trying to make light of a security issue. We take these seriously, and react with patching the more severe vulnerabilities as soon as possible. Others might get prioritized slightly lower, but get addressed nonetheless.

I hope that helps.

---

<div class="post-metadata">

**Author:** ![SwiftPanda16](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/swiftpanda16/32/81839_2.png) [@SwiftPanda16](https://forums.plex.tv/u/SwiftPanda16)\
**Post date:** [January 15, 2026, 6:23pm UTC](https://forums.plex.tv/t/information-related-to-security-vulnerabilities/935164/18 "2026-01-15T18:23:26Z")

</div>

Please don’t remove the shared tokens from `shared_servers`. It is useful for the admin to be able to access their own server as another user through the API. For example, being able to change the audio/subtitle preferences on a show, or synchronizing playlists across users.

---

<div class="post-metadata">

**Author:** ![math4706](https://avatars.discourse-cdn.com/v4/letter/m/f05b48/32.png) [@math4706](https://forums.plex.tv/u/math4706)\
**Post date:** [January 16, 2026, 8:35am UTC](https://forums.plex.tv/t/information-related-to-security-vulnerabilities/935164/19 "2026-01-16T08:35:21Z")

</div>

Hi,

in my Opinion it would help, in general sense, that Plex would provide this kind of information and their own view on the matter, in a more public form. At least when the topic gets published openly in the internet.

For me I can say that I don’t have a good feeling, that I and others have to ask in a forum for a comment on the matter and then wait for days to get some information on it.

I can understand that, if there is a responsible disclosure that you are not commenting on it till it is fixed. But if it is already published on the internet, to ask for information as a customer, is not a thing that makes me feel save with the product.

Mathes

---

<div class="post-metadata">

**Author:** ![math4706](https://avatars.discourse-cdn.com/v4/letter/m/f05b48/32.png) [@math4706](https://forums.plex.tv/u/math4706)\
**Post date:** [January 26, 2026, 1:21pm UTC](https://forums.plex.tv/t/information-related-to-security-vulnerabilities/935164/20 "2026-01-26T13:21:03Z")

</div>

Hi,

is there any news on this topic?

Mathes

---

<div class="post-metadata">

**Author:** ![OttoKerner](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/ottokerner/32/10079_2.png) [@OttoKerner](https://forums.plex.tv/u/OttoKerner)\
**Post date:** [January 26, 2026, 1:23pm UTC](https://forums.plex.tv/t/information-related-to-security-vulnerabilities/935164/21 "2026-01-26T13:23:40Z")

</div>

What news are you expecting?  
The remaining issue is very low-risk.

---

<div class="post-metadata">

**Author:** ![math4706](https://avatars.discourse-cdn.com/v4/letter/m/f05b48/32.png) [@math4706](https://forums.plex.tv/u/math4706)\
**Post date:** [January 28, 2026, 9:21am UTC](https://forums.plex.tv/t/information-related-to-security-vulnerabilities/935164/22 "2026-01-28T09:21:18Z")

</div>

Hi,

maybe I was not good at reading between the lines in the other post above. But as there were some statements in the way of “some things are worked on” or “we are looking into removing the rest”, I assumed that we would get some kind of information if this is now done, or at least some kind of update like “we will do this in the next release”.

But taking your last statement that this a very low issue, I can now assume that nothing more will happen. So now I have to evaluate for myself, if I see it the same way and re-enable the internet access to my instance or not.

Mathes

---

<div class="post-metadata">

**Author:** ![rossinior](https://avatars.discourse-cdn.com/v4/letter/r/5f8ce5/32.png) [@rossinior](https://forums.plex.tv/u/rossinior)\
**Post date:** [January 28, 2026, 9:34am UTC](https://forums.plex.tv/t/information-related-to-security-vulnerabilities/935164/23 "2026-01-28T09:34:27Z")

</div>

> [@OttoKerner](#):
>
> What news are you expecting?  
> The remaining issue is very low-risk.

Well, “fixed” would be good news to read. Together with info on which part of the API changed which way…

I don’t want to bother you, but if you mess with an existing endpoint (documented or not), it would be good practise to communicate changes to it.

[Next page](https://forums.plex.tv/t/information-related-to-security-vulnerabilities/935164.md?page=2)
