CVE-2026-96654: CWE-84 Improper Neutralization of Encoded URI Schemes in a Web Page in Plex Media Server
Plex Media Server before 1.43.3.10861 does not correctly neutralize URL values included in 'searchOne,' allowing an attacker to call other plugins' functions and supply their own parameters.
AI Analysis
Technical Summary
CVE-2026-96654 affects Plex Media Server prior to version 1.43.3.10861. The vulnerability arises because the software does not correctly neutralize URL values included in the 'searchOne' parameter. This improper neutralization enables an attacker to call functions of other plugins and supply their own parameters, which may lead to unexpected or unauthorized actions within the application context. The CVSS 4.0 base score is 6.9, indicating a medium severity level. No known exploits are reported in the wild, and the vulnerability does not require user interaction or privileges to exploit.
Potential Impact
An attacker can leverage this vulnerability to invoke other plugins' functions with attacker-controlled parameters, potentially causing unintended behavior or information disclosure within the Plex Media Server environment. The impact is limited to the scope of plugin functionality accessible via the 'searchOne' parameter and does not involve privilege escalation or remote code execution as per the available data.
Mitigation Recommendations
Upgrade Plex Media Server to version 1.43.3.10861 or later, where this vulnerability has been addressed. No other mitigation or temporary workaround is indicated. Patch status is confirmed by the affectedVersions field indicating fixed versions at 1.43.3.10861.
CVE-2026-96654: CWE-84 Improper Neutralization of Encoded URI Schemes in a Web Page in Plex Media Server
Description
Plex Media Server before 1.43.3.10861 does not correctly neutralize URL values included in 'searchOne,' allowing an attacker to call other plugins' functions and supply their own parameters.
CVSS v4.0
Score 6.9medium
Affected software
Plex
Media Server
pkg:github/plex/plex-media-serverRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-96654 affects Plex Media Server prior to version 1.43.3.10861. The vulnerability arises because the software does not correctly neutralize URL values included in the 'searchOne' parameter. This improper neutralization enables an attacker to call functions of other plugins and supply their own parameters, which may lead to unexpected or unauthorized actions within the application context. The CVSS 4.0 base score is 6.9, indicating a medium severity level. No known exploits are reported in the wild, and the vulnerability does not require user interaction or privileges to exploit.
Potential Impact
An attacker can leverage this vulnerability to invoke other plugins' functions with attacker-controlled parameters, potentially causing unintended behavior or information disclosure within the Plex Media Server environment. The impact is limited to the scope of plugin functionality accessible via the 'searchOne' parameter and does not involve privilege escalation or remote code execution as per the available data.
Mitigation Recommendations
Upgrade Plex Media Server to version 1.43.3.10861 or later, where this vulnerability has been addressed. No other mitigation or temporary workaround is indicated. Patch status is confirmed by the affectedVersions field indicating fixed versions at 1.43.3.10861.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- cisa-cg
- Date Reserved
- 2026-09-23T14:42:18.475Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab3ff4ff7a7c541060b3041
Added to database: 09/23/2026, 16:33:19 UTC
Last enriched: 09/23/2026, 16:47:58 UTC
Last updated: 09/24/2026, 01:57:04 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.