OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-96656

HIGH · CVSS 7.2 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Plex Media Server versions prior to 1.43.3.10861 are vulnerable to a high-severity issue that allows an admin user to write arbitrary files, which can be executed during the transcoding process. This flaw arises from the insecure handling of the TranscoderH264Options preference, enabling potential execution of malicious code without proper verification. Organizations using Plex Media Server, particularly those with administrative access, should prioritize patching this vulnerability to mitigate the risk of unauthorized code execution.

CVE
CVE-2026-96656
Severity
HIGH
CVSS
7.2
EPSS
0.40%

Original NVD Description

Plex Media Server before 1.43.3.10861 allows an admin user to write arbitrary files that may be executed on load. The preference TranscoderH264Options is appended verbatim to x264's option string on every transcode. At startup, all .so files are run without signature, execute bit, or symbol checks.

Related CVEs

Other vulnerabilities affecting the same vendor(s)