OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-96654

MEDIUM · CVSS 6.5 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Plex Media Server versions prior to 1.43.3.10861 are vulnerable due to improper handling of URL values in the 'searchOne' function, which can allow attackers to invoke functions from other plugins with arbitrary parameters. This could lead to unauthorized actions or data exposure within the server environment. Users and administrators of Plex Media Server should prioritize updating to the latest version to mitigate potential exploitation risks.

CVE
CVE-2026-96654
Severity
MEDIUM
CVSS
6.5
EPSS
0.23%

Original NVD Description

Plex Media Server before 1.43.3.10861 does not correctly neutralize URL values included in 'searchOne,' allowing an attacker to call other plugins' functions and supply their own parameters.

Related CVEs

Other vulnerabilities affecting the same vendor(s)