Path Traversal Vulnerability in Plex Media Server by Plex
CVE-2026-96651

7.1HIGH

Key Information:

Vendor

Plex

Vendor
CVE Published:
23 September 2026

What is CVE-2026-96651?

Plex Media Server versions prior to 1.43.3.10861 are vulnerable to a path traversal exploit via the '/system/agents/media/get' endpoint. This vulnerability allows an attacker with a valid session token to manipulate file paths, potentially gaining unauthorized access to sensitive files accessible to the target user, including the PlexOnlineToken, which can be used to take control of the Plex account and server. Attackers on the same LAN, leveraging a client-supplied X-Forwarded-For header, may also exploit this vulnerability.

Affected Version(s)

Media Server 0 < 1.43.3.10861

Media Server 1.43.3.10861

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zach Main
.