6.9

CVE-2026-96654

Plex Media Server URL injection

Plex Media Server before 1.43.3.10861 does not correctly neutralize URL values included in 'searchOne,' allowing an attacker to call other plugins' functions and supply their own parameters.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Plex ≫ Media Server Version < 1.43.0.10861
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.107
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
cisa-cg 6.9 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
cisa-cg 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CWE-84 Improper Neutralization of Encoded URI Schemes in a Web Page

The web application improperly neutralizes user-controlled input for executable script disguised with URI encodings.

https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-266-01.json
Third Party Advisory
https://forums.plex.tv/t/plex-media-server/30447/711
Release Notes
https://zmain.info/blog/plex2shell
Third Party Advisory
https://www.cve.org/CVERecord?id=CVE-2026-96654
Third Party Advisory
VDB Entry