CVE-2026-96655 Overview
CVE-2026-96655 is a Server-Side Request Forgery (SSRF) vulnerability in Plex Media Server versions before 1.43.3.10861. An authenticated user can abuse the /video/:/transcode/universal path parameter to force the server to issue HTTP requests to arbitrary internal or external addresses. The flaw is categorized under CWE-918: Server-Side Request Forgery and enables attackers to pivot from an authenticated Plex session into internal network resources normally unreachable from the internet.
Critical Impact
Authenticated attackers can leverage the Plex Media Server as an SSRF proxy to reach internal-only services, cloud metadata endpoints, and other restricted network resources.
Affected Products
- Plex Media Server versions prior to 1.43.3.10861
- All platform builds (Windows, macOS, Linux, NAS) sharing the affected transcoder code path
- Deployments exposing the /video/:/transcode/universal endpoint to authenticated users
Discovery Timeline
- 2026-09-23 - CVE-2026-96655 published to NVD
- 2026-09-23 - Last updated in NVD database
Technical Details for CVE-2026-96655
Vulnerability Analysis
The vulnerability resides in Plex Media Server's universal transcoding endpoint at /video/:/transcode/universal. The endpoint accepts a path parameter that is used to construct an outbound HTTP request. Plex does not sufficiently validate or restrict the destination of that request. An authenticated user can supply an arbitrary URL, causing the server to fetch content from internal network hosts, loopback interfaces, or external systems on the attacker's behalf.
This SSRF primitive can be chained with follow-on techniques. Public research published as Plex2Shell on the Zmain blog documents how the transcoder request handling can be abused as part of a broader attack chain against Plex deployments.
Root Cause
The root cause is missing destination validation on a user-influenced URL parameter passed to the transcoder. The application trusts the authenticated caller to supply a legitimate media source, then dispatches an outbound request without enforcing an allowlist of hosts, protocols, or IP ranges. Requests to private address space (RFC1918), link-local ranges, loopback, and cloud metadata services (169.254.169.254) are not blocked.
Attack Vector
Exploitation requires an authenticated Plex account with access to the transcoder endpoint. The attacker issues a crafted GET request to /video/:/transcode/universal with a manipulated path parameter pointing at an internal or external URL. Plex Media Server then performs the outbound HTTP request from the server's network position, returning response data or side-effect behavior to the attacker.
Because the server originates the request, the attacker inherits Plex's network reachability. This enables reconnaissance of internal services, interaction with unauthenticated admin panels on the same subnet, and retrieval of cloud instance metadata when Plex runs on AWS, Azure, or GCP hosts. The vulnerability does not directly grant code execution, but SSRF often serves as a precursor to deeper compromise, as demonstrated in the Plex2Shell research.
Detection Methods for CVE-2026-96655
Indicators of Compromise
- Unexpected outbound HTTP requests from the Plex Media Server process to internal IP ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) or loopback
- Requests originating from Plex to cloud metadata endpoints such as 169.254.169.254
- High-volume or unusual requests to /video/:/transcode/universal with encoded URLs in the path parameter
- Authentication events from Plex accounts followed immediately by anomalous transcoder activity
Detection Strategies
- Inspect Plex access logs for /video/:/transcode/universal requests containing embedded URLs, IP addresses, or non-media schemes in the path parameter
- Correlate authenticated Plex sessions with outbound network flows from the Plex host to unexpected destinations
- Deploy network detection rules that alert on Plex-originated traffic crossing segmentation boundaries into management or infrastructure VLANs
- Baseline normal transcoder destinations and alert on deviations, particularly requests to private IP space
Monitoring Recommendations
- Forward Plex Media Server logs and host-level network telemetry to a centralized analytics platform for correlation
- Enable egress flow logging on the network segment hosting Plex to identify SSRF pivot attempts
- Monitor for authentication anomalies on Plex accounts, including credential reuse and new device registrations, since exploitation requires an authenticated session
- Track process-level network connections from the Plex Media Server binary to detect unexpected outbound destinations
How to Mitigate CVE-2026-96655
Immediate Actions Required
- Upgrade Plex Media Server to version 1.43.3.10861 or later on all deployments
- Audit Plex user accounts and remove or disable accounts that are no longer required
- Restrict Plex Media Server outbound network access using host or perimeter firewall rules to only the destinations required for legitimate operation
- Review authentication and access logs for suspicious transcoder requests prior to patching
Patch Information
Plex has released a fixed version. Upgrade to Plex Media Server 1.43.3.10861 or later. Refer to the Plex Forum discussion for release details and the CISA CSAF advisory for structured vulnerability metadata. The official CVE-2026-96655 record tracks upstream changes.
Workarounds
- Place Plex Media Server behind a reverse proxy or WAF that inspects and blocks requests to /video/:/transcode/universal containing suspicious URL patterns in the path parameter
- Apply egress filtering so the Plex host cannot reach internal management networks, cloud metadata endpoints, or unrelated internet destinations
- Deploy Plex on an isolated network segment with no lateral reachability to sensitive infrastructure
- Require strong authentication and disable account sharing to limit the population of users capable of triggering the endpoint
# Example iptables egress restriction blocking Plex from reaching cloud metadata and RFC1918 networks
iptables -A OUTPUT -m owner --uid-owner plex -d 169.254.169.254 -j DROP
iptables -A OUTPUT -m owner --uid-owner plex -d 10.0.0.0/8 -j DROP
iptables -A OUTPUT -m owner --uid-owner plex -d 172.16.0.0/12 -j DROP
iptables -A OUTPUT -m owner --uid-owner plex -d 192.168.0.0/16 -j DROP
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.