CVE-2026-96654 Overview
CVE-2026-96654 affects Plex Media Server versions prior to 1.43.3.10861. The vulnerability stems from improper neutralization of URL values passed through the searchOne parameter. An attacker can leverage this flaw to invoke functions in other plugins and supply arbitrary parameters to them. The issue is classified under CWE-84: Improper Neutralization of Encoded URI Schemes in a Web Page. Because the flaw is reachable over the network without authentication, remote attackers can abuse plugin functionality outside of intended trust boundaries.
Critical Impact
Remote unauthenticated attackers can cross plugin boundaries in Plex Media Server, invoking plugin functions with attacker-controlled parameters and undermining confidentiality and integrity of media server operations.
Affected Products
- Plex Media Server versions before 1.43.3.10861
- Deployments exposing the Plex web interface to untrusted networks
- Installations running third-party or built-in plugins reachable via searchOne
Discovery Timeline
- 2026-09-23 - CVE-2026-96654 published to the National Vulnerability Database (NVD)
- 2026-09-23 - Last updated in NVD database
Technical Details for CVE-2026-96654
Vulnerability Analysis
The vulnerability resides in how Plex Media Server processes URL values submitted through the searchOne parameter. The server fails to neutralize or validate the URL content before routing it through the plugin dispatch layer. As a result, an attacker can craft a URL that references functions belonging to other plugins loaded in the server. The attacker can also supply parameters that those target functions accept, bypassing intended plugin isolation. Public discussion on the Plex forums and the Zmain writeup on Plex2Shell provide additional operational context.
Root Cause
The root cause is improper input neutralization of a URL-typed parameter [CWE-84]. searchOne accepts a value that is interpreted as a routable reference within the plugin subsystem. Without sanitization of the URI scheme, path, or query components, the value can resolve to unintended plugin endpoints. This design permits cross-plugin function invocation that the trust model does not anticipate.
Attack Vector
The attack vector is network-based and requires no authentication or user interaction. An attacker sends a crafted HTTP request to a vulnerable Plex Media Server, embedding a malicious URL in searchOne. The server dispatches the request to a plugin function chosen by the attacker, passing attacker-supplied arguments. Detailed exploitation mechanics are covered in the Plex Forum discussion and the CVE-2026-96654 record. No verified proof-of-concept code is reproduced here; refer to the referenced writeups for technical detail.
Detection Methods for CVE-2026-96654
Indicators of Compromise
- HTTP requests to Plex Media Server containing a searchOne parameter whose value encodes a URL referencing plugin functions unrelated to search.
- Log entries showing plugin function invocations that do not correspond to normal user-driven search or browse activity.
- Unexpected outbound requests initiated by Plex plugins immediately after inbound searchOne traffic.
Detection Strategies
- Inspect Plex access logs for searchOne values that contain URL-encoded characters, plugin identifiers, or nested query strings.
- Correlate inbound requests with plugin execution telemetry to identify cross-plugin invocations triggered by external clients.
- Baseline normal Plex plugin traffic and alert on deviations, particularly requests originating from external or non-corporate IP ranges.
Monitoring Recommendations
- Forward Plex Media Server logs to a centralized logging or SIEM platform and retain them for at least 90 days.
- Monitor the Plex process for unexpected child processes or file writes following inbound web requests.
- Track the installed Plex Media Server version across all hosts and alert when versions below 1.43.3.10861 are detected.
How to Mitigate CVE-2026-96654
Immediate Actions Required
- Upgrade all Plex Media Server instances to version 1.43.3.10861 or later.
- Restrict remote access to the Plex web interface using firewall rules or a reverse proxy with authentication.
- Audit installed plugins and remove any that are unused or untrusted to reduce the attackable function surface.
Patch Information
Plex resolved the vulnerability in Plex Media Server 1.43.3.10861. Version details and vendor communication are referenced in the Plex Forum announcement thread and the CISA CSAF advisory document. Administrators should update through the standard Plex update channel and verify the running version after restart.
Workarounds
- Block external access to the Plex Media Server port at the network perimeter until the patch is applied.
- Place Plex behind a reverse proxy that filters requests containing suspicious searchOne values.
- Limit Plex access to trusted internal networks or VPN clients only.
# Example: restrict Plex Media Server port 32400 to a trusted subnet using iptables
iptables -A INPUT -p tcp --dport 32400 -s 10.0.0.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 32400 -j DROP
# Verify the installed Plex Media Server version on Linux
dpkg -l | grep plexmediaserver
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.