PatchSiren cyber security CVE debrief
CVE-2026-96651 Plex CVE debrief
A path traversal vulnerability exists in Plex Media Server before version 1.43.3.10861. The issue allows a remote attacker with a valid session token to read any file accessible by the target user, including the PlexOnlineToken which could grant control over the Plex account and server. This vulnerability is particularly concerning because it can be exploited by a remote attacker with a valid session token, potentially leading to unauthorized access to sensitive files and data. Defenders should assess their exposure and take remediation steps to prevent potential unauthorized access and exposure of sensitive information.
- Vendor
- Plex
- Product
- Media Server
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-23
- Original CVE updated
- 2026-09-29
- Advisory published
- 2026-09-23
- Advisory updated
- 2026-09-29
Who should care
Defenders responsible for Plex Media Server installations, particularly those with exposed instances or sensitive data stored on the server, should assess their exposure and take remediation steps.
Why it matters
CVE-2026-96651 is a high-severity path traversal vulnerability in Plex Media Server that allows remote attackers to read sensitive files. Defenders should prioritize verification, remediation, and monitoring to prevent potential unauthorized access and exposure of sensitive information.
- Potential unauthorized access to sensitive files
- Possible exposure of the PlexOnlineToken
- Required verification of Plex Media Server version and exposure
- Necessity to restrict access to sensitive files and monitor for suspicious activity
Technical summary
The vulnerability exists in Plex Media Server before version 1.43.3.10861, where the application builds a file path from the url parameter without checking for ../ sequences. This allows a remote attacker with a valid session token to read any file accessible by the target user. The vulnerability is a result of insufficient validation of user-supplied input, which enables an attacker to traverse the file system and access sensitive files. Defenders should prioritize verifying and upgrading to version 1.43.3.10861 or later, restricting access to sensitive files, and monitoring for suspicious file access attempts.
Defensive priority
Defenders should prioritize verifying and upgrading to version 1.43.3.10861 or later, restricting access to sensitive files, and monitoring for suspicious file access attempts.
Recommended defensive actions
- Verify and upgrade Plex Media Server to version 1.43.3.10861 or later
- Restrict access to sensitive files and monitor for suspicious file access attempts
- Rotate the PlexOnlineToken and ensure it is not exposed
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. Release notes and third-party advisories offer additional context. The vulnerability has been confirmed in Plex Media Server versions prior to 1.43.3.10861. Defenders should verify the version of Plex Media Server in use and review the official advisory for specific guidance on remediation. Evidence is limited to public sources and may not reflect the full scope of affected systems or potential impacts.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-96651 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-96651
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-96651 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-96651
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://forums.plex.tv/t/plex-media-server/30447/711
9119a7d8-5eab-497f-8521-727c672e3725 - Release Notes
-
Source reference
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-266-01.json
9119a7d8-5eab-497f-8521-727c672e3725 - Third Party Advisory
-
Source reference
Unverified legacy reference
URL: https://zmain.info/blog/plex2shell
9119a7d8-5eab-497f-8521-727c672e3725 - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.