news.mlab.sh
Back to the feed
vulnerability

Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws

HighCVSS 8.5
Summary

Plex is urging users to immediately update their media server and desktop applications to address multiple undisclosed security flaws. These vulnerabilities could allow attackers to expose server details and potentially launch denial-of-service attacks, highlighting a recurring issue with Plex Media Server security.

Plex has issued a call to action, requesting that all users update their Plex Media Server and Plex Desktop applications to the latest version. The company has not disclosed the specific details of the vulnerabilities, but has indicated that CVE identifiers have been requested.

In August 2025, Plex addressed a high-severity security flaw (CVE-2025-34158, CVSS score: 8.5) related to an authentication issue. This flaw stemmed from the '/myplex/account' endpoint incorrectly exposing server owner account details, including administrative access tokens, even when accessed by non-owner or lower-privileged users. Furthermore, a subsequent '/api/resources' API call can be used to reveal other servers accessible by that server owner, potentially exposing the owner's entire Plex infrastructure to unauthorized access – creating an exploit chain.

Data from Censys shows that over 360,000 devices are currently exposing the Plex Media Server web interface, though not all of these devices are necessarily vulnerable. Historically, vulnerabilities in Plex Media Server have been exploited by threat actors. In February 2021, Plex released a security update to mitigate a denial-of-service attack, where attackers were able to cause an affected server to "reflect" UDP packets to amplify DoS attacks against other servers.

This ongoing issue underscores the importance of timely updates and proactive security measures for Plex users.

Read the full article at The Hacker News