CVE-2026-96655

Plex Media Server before 1.43.3.10861 allows an authenticated user to request arbitrary internal or external addresses via the '/video/:/transcode/universal' path parameter.

  • Published Sep 23, 2026
  • CVSS 5.3 medium
  • 0.2% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-96655 at the National Vulnerability Database