CVE-2026-96652: Plex Media Server

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Plex Media Server before 1.43.3.10861 allows SSRF via '/player/timeline'. An attacker using any X-Plex-Token value can include a full URL in the 'protocol' parameter and force the Plex server to POST to the attacker's chosen destination.

Affected products

  • Plex Media Server: before 1.43.0.10861 (fixed in 1.43.0.10861)

Published 2026-09-23. Last modified 2026-09-29.