CVE-2026-96655: Plex Media Server
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Plex Media Server before 1.43.3.10861 allows an authenticated user to request arbitrary internal or external addresses via the '/video/:/transcode/universal' path parameter.
Affected products
- Plex Media Server: before 1.43.0.10861 (fixed in 1.43.0.10861)
Published 2026-09-23. Last modified 2026-09-29.