OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-96652

MEDIUM · CVSS 4.3 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Plex Media Server versions prior to 1.43.3.10861 are vulnerable to Server-Side Request Forgery (SSRF) through the '/player/timeline' endpoint, allowing attackers to exploit the 'protocol' parameter with any X-Plex-Token value. This vulnerability enables unauthorized POST requests to arbitrary URLs, potentially leading to data exposure or further attacks on internal systems. Organizations using affected versions of Plex Media Server should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-96652
Severity
MEDIUM
CVSS
4.3
EPSS
0.22%

Original NVD Description

Plex Media Server before 1.43.3.10861 allows SSRF via '/player/timeline'. An attacker using any X-Plex-Token value can include a full URL in the 'protocol' parameter and force the Plex server to POST to the attacker's chosen destination.

Related CVEs

Other vulnerabilities affecting the same vendor(s)