MEDIUM 6.9 NVD
CVE-2026-96654
Plex Media Server before 1.43.3.10861 does not correctly neutralize URL values included in 'searchOne,' allowing an attacker to call other plugins' functions an
Plex Media Server before 1.43.3.10861 does not correctly neutralize URL values included in 'searchOne,' allowing an attacker to call other plugins' functions and supply their own parameters.
References
- https://forums.plex.tv/t/plex-media-server/30447/711
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-266-
- https://www.cve.org/CVERecord?id=CVE-2026-96654
- https://zmain.info/blog/plex2shell
This medium severity vulnerability with a CVSS score of 6.9 was published on 2026-09-23 via NVD.
vulnfeed aggregates 12908 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.