Skip to main content
Vulnerability Database/CVE-2026-96652

CVE-2026-96652: Plex Media Server SSRF Vulnerability

CVE-2026-96652 is a server-side request forgery flaw in Plex Media Server that allows attackers to force the server to make POST requests to arbitrary destinations. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-96652 Overview

CVE-2026-96652 is a Server-Side Request Forgery (SSRF) vulnerability in Plex Media Server versions prior to 1.43.3.10861. The flaw resides in the /player/timeline endpoint, which accepts a full URL in the protocol parameter. An attacker authenticated with any valid X-Plex-Token value can coerce the Plex server to issue HTTP POST requests to arbitrary destinations of their choosing. The vulnerability is classified as CWE-918: Server-Side Request Forgery.

Critical Impact

Authenticated attackers can pivot through the Plex server to reach internal network resources, cloud metadata endpoints, and other services not directly exposed to the internet.

Affected Products

  • Plex Media Server versions prior to 1.43.3.10861
  • Deployments exposing the /player/timeline endpoint to untrusted clients
  • Self-hosted and NAS-based Plex installations across supported operating systems

Discovery Timeline

  • 2026-09-23 - CVE-2026-96652 published to the National Vulnerability Database (NVD)
  • 2026-09-23 - Last updated in NVD database

Technical Details for CVE-2026-96652

Vulnerability Analysis

The vulnerability exists in how Plex Media Server handles the protocol parameter passed to the /player/timeline endpoint. Instead of restricting the parameter to expected protocol scheme values, the server accepts an arbitrary full URL. Plex then uses that URL as the destination for an outbound HTTP POST request originating from the server process.

Any caller presenting a valid X-Plex-Token header can trigger this behavior. The token check does not validate the destination or restrict it to trusted hosts. As a result, the Plex server becomes a proxy for attacker-controlled outbound requests. Additional analysis is available in the Zmain blog on Plex2Shell and the Plex forum discussion.

Root Cause

The root cause is missing input validation on the protocol request parameter. The endpoint treats the value as a trusted URL rather than restricting it to an allow-list of protocol identifiers. This allows attackers to substitute an absolute URL and hijack the destination of the server-side request.

Attack Vector

Exploitation requires network access to the Plex Media Server web interface and any X-Plex-Token value. The attacker sends a crafted request to /player/timeline with the protocol parameter set to a URL under their control or targeting an internal service. The Plex server then issues an HTTP POST to that URL. This can be used to probe internal networks, reach cloud instance metadata services, or interact with services that trust requests originating from the Plex host.

No verified public exploit code is referenced by NVD. Refer to the CVE-2026-96652 record and the CISA CSAF advisory for authoritative details.

Detection Methods for CVE-2026-96652

Indicators of Compromise

  • HTTP requests to /player/timeline containing a fully qualified URL in the protocol query parameter
  • Outbound HTTP POST connections originating from the Plex Media Server process to unexpected internal or external hosts
  • Access attempts from the Plex server to cloud metadata endpoints such as 169.254.169.254
  • Repeated /player/timeline calls from a single source using varied X-Plex-Token values

Detection Strategies

  • Inspect reverse proxy and web server access logs for /player/timeline requests where the protocol parameter begins with http:// or https://
  • Correlate inbound Plex API calls with outbound POST connections from the Plex host to identify SSRF pivoting
  • Alert on outbound traffic from Plex servers to RFC1918 ranges, link-local addresses, or cloud metadata IPs

Monitoring Recommendations

  • Enable egress traffic logging on hosts running Plex Media Server and forward to a centralized log store
  • Baseline expected outbound destinations for Plex and alert on deviations
  • Monitor the Plex application logs for unusual protocol parameter values and elevated /player/timeline request volumes

How to Mitigate CVE-2026-96652

Immediate Actions Required

  • Upgrade Plex Media Server to version 1.43.3.10861 or later on all hosts
  • Restrict access to the Plex web interface to trusted networks using firewall rules or VPN
  • Rotate any X-Plex-Token values that may have been exposed to untrusted clients
  • Audit outbound network activity from Plex hosts for signs of prior SSRF exploitation

Patch Information

Plex addressed the vulnerability in Plex Media Server 1.43.3.10861. Administrators should apply the update through the standard Plex update channel or by downloading the current release from the vendor. Verify the installed version after upgrade to confirm remediation.

Workarounds

  • Place Plex Media Server behind a reverse proxy that strips or validates the protocol parameter on /player/timeline
  • Apply egress firewall rules that deny outbound requests from the Plex host to internal management networks and cloud metadata endpoints
  • Isolate the Plex host on a dedicated network segment with no route to sensitive internal services
bash
# Example egress restriction using iptables to block cloud metadata access
iptables -A OUTPUT -m owner --uid-owner plex -d 169.254.169.254 -j DROP
iptables -A OUTPUT -m owner --uid-owner plex -d 10.0.0.0/8 -j DROP
iptables -A OUTPUT -m owner --uid-owner plex -d 172.16.0.0/12 -j DROP
iptables -A OUTPUT -m owner --uid-owner plex -d 192.168.0.0/16 -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.