CVE-2026-96654EPSS p12.3%

CVE-2026-96654CVE-2026-96654

plex / media_server

Description

Plex Media Server before 1.43.3.10861 does not correctly neutralize URL values included in 'searchOne,' allowing an attacker to call other plugins' functions and supply their own parameters.

Scoring

CVSS 6.5 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS0.23% probability of exploitation · percentile 12.3% · 2026-10-06T12:00:23Z
Last modified2026-09-29
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.