Server-Side Request Forgery Vulnerability in Plex Media Server
CVE-2026-96652
5.3MEDIUM
What is CVE-2026-96652?
A vulnerability exists in Plex Media Server that allows for Server-Side Request Forgery (SSRF) through the '/player/timeline' endpoint. By exploiting this flaw, an attacker can manipulate the 'protocol' parameter using any X-Plex-Token value, enabling them to send POST requests to any external destination of their choosing. This could lead to unauthorized access to sensitive data or services, underscoring the need for users to update to the latest version to mitigate potential risks.
Affected Version(s)
Media Server 0 < 1.43.3.10861
Media Server 1.43.3.10861
