CVE-2026-96651 Overview
CVE-2026-96651 is a path traversal vulnerability [CWE-22] in Plex Media Server versions before 1.43.3.10861. The server constructs a file path from the url parameter of the /system/agents/media/get endpoint without validating ../ sequences. A remote attacker holding a valid session token can read arbitrary files accessible to the Plex process user. Retrievable data includes the PlexOnlineToken, which grants full control over the associated Plex account and server. A LAN-adjacent attacker can achieve the same result by supplying a crafted X-Forwarded-For header.
Critical Impact
Successful exploitation exposes the PlexOnlineToken, allowing attackers to hijack the Plex account and take control of the media server.
Affected Products
- Plex Media Server versions prior to 1.43.3.10861
- Deployments exposing the web API to untrusted networks
- Instances behind reverse proxies that forward client-supplied X-Forwarded-For headers
Discovery Timeline
- 2026-09-23 - CVE-2026-96651 published to NVD
- 2026-09-23 - Last updated in NVD database
Technical Details for CVE-2026-96651
Vulnerability Analysis
The flaw resides in the /system/agents/media/get endpoint of Plex Media Server. The handler takes the url request parameter and joins it into a server-side file path used to fetch agent media. No canonicalization or sanitization is applied before the join, so directory traversal sequences resolve outside the intended media directory.
An authenticated attacker can request arbitrary files that the Plex service account can read. On typical installations this includes the Preferences file that stores PlexOnlineToken, database files, and other user-readable content on the host. Because the token authorizes API operations against Plex.tv and the local server, disclosure results in full account and server takeover.
The vulnerability is also reachable in a LAN-adjacent context. When Plex trusts a client-supplied X-Forwarded-For header for authorization decisions, an unauthenticated attacker on the local network can spoof the header and reach the same endpoint without a valid session token.
Root Cause
The root cause is missing input validation on a user-controlled path component [CWE-22]. The url parameter is concatenated into a filesystem path without rejecting .., absolute paths, or encoded traversal sequences, and without confirming the resolved path remains within the expected base directory.
Attack Vector
Exploitation requires network access to the Plex Media Server web interface and either a valid Plex session token or the ability to send a spoofed X-Forwarded-For header from an adjacent network segment. The attacker issues a GET request to /system/agents/media/get with a url parameter containing traversal sequences that resolve to sensitive files such as the Plex Preferences XML. The response returns the requested file contents, from which the PlexOnlineToken and other secrets can be extracted.
See the Zmain Blog Post on Plex2Shell and the CISA CSAF Vulnerability Report for additional technical detail.
Detection Methods for CVE-2026-96651
Indicators of Compromise
- HTTP requests to /system/agents/media/get containing ../, ..%2f, or URL-encoded traversal sequences in the url parameter.
- Requests to that endpoint carrying an X-Forwarded-For header sourced from untrusted or external clients.
- Unexpected reads of Preferences.xml or database files by the Plex Media Server process.
- Sudden changes to Plex account settings, new authorized devices, or session activity from unfamiliar geographies indicating stolen PlexOnlineToken reuse.
Detection Strategies
- Inspect Plex access logs for the /system/agents/media/get path and flag any request whose url parameter decodes to a path outside the expected agents media directory.
- Correlate traversal patterns with authenticated session identifiers to identify compromised accounts.
- Alert on requests where X-Forwarded-For differs from the true source IP for internet-exposed Plex instances.
Monitoring Recommendations
- Forward Plex Media Server logs and reverse proxy logs to a centralized analytics platform for retention and correlation.
- Monitor filesystem access to the Plex application data directory for reads originating from web request handlers.
- Track outbound API calls made using the PlexOnlineToken and alert on unexpected client identifiers or source addresses.
How to Mitigate CVE-2026-96651
Immediate Actions Required
- Upgrade Plex Media Server to version 1.43.3.10861 or later on all hosts.
- After patching, rotate the PlexOnlineToken by signing out of all devices in the Plex account and re-authenticating.
- Audit account activity, authorized devices, and server claim status for signs of prior misuse.
- Restrict inbound access to the Plex web interface to trusted networks or a VPN until patching is complete.
Patch Information
The vendor has resolved the issue in Plex Media Server 1.43.3.10861. Refer to the Plex Forum Discussion and the CVE-2026-96651 Record for release details.
Workarounds
- Place Plex Media Server behind a reverse proxy that strips or overwrites client-supplied X-Forwarded-For headers before forwarding.
- Block external access to the /system/agents/media/get endpoint at the proxy or firewall until patches are applied.
- Run the Plex service under a dedicated low-privilege account with filesystem access limited to required media and configuration paths.
# Example NGINX reverse proxy hardening: overwrite client X-Forwarded-For
# and block direct access to the vulnerable endpoint until patched.
location /system/agents/media/get {
return 403;
}
location / {
proxy_set_header X-Forwarded-For $remote_addr;
proxy_set_header X-Real-IP $remote_addr;
proxy_pass http://127.0.0.1:32400;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.