CVE-2026-96655: Plex Media Server

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Plex Media Server before 1.43.3.10861 allows an authenticated user to request arbitrary internal or external addresses via the '/video/:/transcode/universal' path parameter.

Affected products

  • Plex Media Server: before 1.43.0.10861 (fixed in 1.43.0.10861)

Published 2026-09-23. Last modified 2026-09-29.