In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether the device is currently associated with an account.
Plex Media Server versions through 1.42.2.10156 contain an authentication bypass vulnerability where device tokens can access /myplex/account endpoints even after device disassociation. This CWE-672 flaw allows unauthorized access to account information through improperly validated device tokens, with active exploits available and no patch currently released.
Queued for AI Analysis
This CVE will be auto-analyzed on the next cron run.