CVE-2026-96652 Overview
CVE-2026-96652 is a Server-Side Request Forgery (SSRF) vulnerability in Plex Media Server versions prior to 1.43.3.10861. The flaw resides in the /player/timeline endpoint, which accepts a full URL in the protocol parameter. An attacker authenticated with any valid X-Plex-Token value can coerce the Plex server to issue HTTP POST requests to arbitrary destinations of their choosing. The vulnerability is classified as CWE-918: Server-Side Request Forgery.
Critical Impact
Authenticated attackers can pivot through the Plex server to reach internal network resources, cloud metadata endpoints, and other services not directly exposed to the internet.
Affected Products
- Plex Media Server versions prior to 1.43.3.10861
- Deployments exposing the /player/timeline endpoint to untrusted clients
- Self-hosted and NAS-based Plex installations across supported operating systems
Discovery Timeline
- 2026-09-23 - CVE-2026-96652 published to the National Vulnerability Database (NVD)
- 2026-09-23 - Last updated in NVD database
Technical Details for CVE-2026-96652
Vulnerability Analysis
The vulnerability exists in how Plex Media Server handles the protocol parameter passed to the /player/timeline endpoint. Instead of restricting the parameter to expected protocol scheme values, the server accepts an arbitrary full URL. Plex then uses that URL as the destination for an outbound HTTP POST request originating from the server process.
Any caller presenting a valid X-Plex-Token header can trigger this behavior. The token check does not validate the destination or restrict it to trusted hosts. As a result, the Plex server becomes a proxy for attacker-controlled outbound requests. Additional analysis is available in the Zmain blog on Plex2Shell and the Plex forum discussion.
Root Cause
The root cause is missing input validation on the protocol request parameter. The endpoint treats the value as a trusted URL rather than restricting it to an allow-list of protocol identifiers. This allows attackers to substitute an absolute URL and hijack the destination of the server-side request.
Attack Vector
Exploitation requires network access to the Plex Media Server web interface and any X-Plex-Token value. The attacker sends a crafted request to /player/timeline with the protocol parameter set to a URL under their control or targeting an internal service. The Plex server then issues an HTTP POST to that URL. This can be used to probe internal networks, reach cloud instance metadata services, or interact with services that trust requests originating from the Plex host.
No verified public exploit code is referenced by NVD. Refer to the CVE-2026-96652 record and the CISA CSAF advisory for authoritative details.
Detection Methods for CVE-2026-96652
Indicators of Compromise
- HTTP requests to /player/timeline containing a fully qualified URL in the protocol query parameter
- Outbound HTTP POST connections originating from the Plex Media Server process to unexpected internal or external hosts
- Access attempts from the Plex server to cloud metadata endpoints such as 169.254.169.254
- Repeated /player/timeline calls from a single source using varied X-Plex-Token values
Detection Strategies
- Inspect reverse proxy and web server access logs for /player/timeline requests where the protocol parameter begins with http:// or https://
- Correlate inbound Plex API calls with outbound POST connections from the Plex host to identify SSRF pivoting
- Alert on outbound traffic from Plex servers to RFC1918 ranges, link-local addresses, or cloud metadata IPs
Monitoring Recommendations
- Enable egress traffic logging on hosts running Plex Media Server and forward to a centralized log store
- Baseline expected outbound destinations for Plex and alert on deviations
- Monitor the Plex application logs for unusual protocol parameter values and elevated /player/timeline request volumes
How to Mitigate CVE-2026-96652
Immediate Actions Required
- Upgrade Plex Media Server to version 1.43.3.10861 or later on all hosts
- Restrict access to the Plex web interface to trusted networks using firewall rules or VPN
- Rotate any X-Plex-Token values that may have been exposed to untrusted clients
- Audit outbound network activity from Plex hosts for signs of prior SSRF exploitation
Patch Information
Plex addressed the vulnerability in Plex Media Server 1.43.3.10861. Administrators should apply the update through the standard Plex update channel or by downloading the current release from the vendor. Verify the installed version after upgrade to confirm remediation.
Workarounds
- Place Plex Media Server behind a reverse proxy that strips or validates the protocol parameter on /player/timeline
- Apply egress firewall rules that deny outbound requests from the Plex host to internal management networks and cloud metadata endpoints
- Isolate the Plex host on a dedicated network segment with no route to sensitive internal services
# Example egress restriction using iptables to block cloud metadata access
iptables -A OUTPUT -m owner --uid-owner plex -d 169.254.169.254 -j DROP
iptables -A OUTPUT -m owner --uid-owner plex -d 10.0.0.0/8 -j DROP
iptables -A OUTPUT -m owner --uid-owner plex -d 172.16.0.0/12 -j DROP
iptables -A OUTPUT -m owner --uid-owner plex -d 192.168.0.0/16 -j DROP
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.