Path Traversal Vulnerability in Plex Media Server by Plex
CVE-2026-96651
7.1HIGH
What is CVE-2026-96651?
Plex Media Server versions prior to 1.43.3.10861 are vulnerable to a path traversal exploit via the '/system/agents/media/get' endpoint. This vulnerability allows an attacker with a valid session token to manipulate file paths, potentially gaining unauthorized access to sensitive files accessible to the target user, including the PlexOnlineToken, which can be used to take control of the Plex account and server. Attackers on the same LAN, leveraging a client-supplied X-Forwarded-For header, may also exploit this vulnerability.
Affected Version(s)
Media Server 0 < 1.43.3.10861
Media Server 1.43.3.10861
