CVE-2026-96652: Plex Media Server SSRF
Published Sep 23, 2026
·Updated
Plex Media Server before 1.43.3.10861 allows SSRF via '/player/timeline'. An attacker using any X-Plex-Token value can include a full URL in the 'protocol' parameter and force the Plex server to POST to the attacker's chosen destination.
Affected Software
1 affected component
Plex Plex Media Server<1.43.3.10861
Event History
Sep 23, 2026
CVE Published
via MITRE·04:06 PM
Data Sourced
via MITRE·04:06 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attacker needs any value in the X-Plex-Token header. No user interaction is required, and the vulnerable endpoint is reachable over the network.
2
What can an attacker make the Plex server do?
An attacker can supply a full URL in the protocol parameter of /player/timeline, causing the Plex server to send a POST request to an attacker-chosen destination.
3
Which Plex Media Server versions are affected?
Plex Media Server versions before 1.43.3.10861 are affected. The provided data does not identify any workaround for systems that cannot be updated immediately.