CVE-2025-34158

P

lex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/account provides the credentials of the server owner (and a /api/resources call reveals other servers accessible by that server owner).

Configurations

No configuration.

History

02 Jan 2026, 16:15

Type Values Removed Values Added
References
  • () https://github.com/lufinkey/vulnerability-research/blob/main/CVE-2025-34158/README.md -
Summary (en) Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres. (en) Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/account provides the credentials of the server owner (and a /api/resources call reveals other servers accessible by that server owner).

28 Aug 2025, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-21 14:15

Updated : 2026-01-02 16:15


NVD link : CVE-2025-34158

Mitre link : CVE-2025-34158

CVE.ORG link : CVE-2025-34158


JSON object : View

Products Affected

No product.

CWE
CWE-669

Incorrect Resource Transfer Between Spheres