CVE-2026-96654
Awaiting Analysis
Awaiting Analysis - Queue
Plex Media Server Plugin Function Parameter Injection
Vulnerability report for CVE-2026-96654, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-23
Last updated on: 2026-09-23
Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government
Description
Description
Plex Media Server before 1.43.3.10861 does not correctly neutralize URL values included in 'searchOne,' allowing an attacker to call other plugins' functions and supply their own parameters.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| plex | media_server | to 1.43.3.10861 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-84 | The web application improperly neutralizes user-controlled input for executable script disguised with URI encodings. |