Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access token.
Plex Media Server versions through 1.42.2.10156 contain an authorization bypass vulnerability (CWE-863) allowing attackers to escalate transient access tokens to permanent tokens via the /myplex/account endpoint. With a CVSS score of 8.5 and active exploits available, this critical flaw enables persistent unauthorized access to media servers and user accounts.
Queued for AI Analysis
This CVE will be auto-analyzed on the next cron run.