OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-96655

MEDIUM · CVSS 4.3 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Plex Media Server versions prior to 1.43.3.10861 are vulnerable to a security flaw that allows authenticated users to exploit the '/video/:/transcode/universal' path to request arbitrary internal or external addresses. This could lead to unauthorized access to sensitive resources or services within the network. Organizations using affected versions should prioritize patching to mitigate potential risks associated with this vulnerability.

CVE
CVE-2026-96655
Severity
MEDIUM
CVSS
4.3
EPSS
0.22%

Original NVD Description

Plex Media Server before 1.43.3.10861 allows an authenticated user to request arbitrary internal or external addresses via the '/video/:/transcode/universal' path parameter.

Related CVEs

Other vulnerabilities affecting the same vendor(s)