CVE-2026-96654: Plex Media Server
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Plex Media Server before 1.43.3.10861 does not correctly neutralize URL values included in 'searchOne,' allowing an attacker to call other plugins' functions and supply their own parameters.
Affected products
- Plex Media Server: before 1.43.0.10861 (fixed in 1.43.0.10861)
Published 2026-09-23. Last modified 2026-09-29.