{"cve":"CVE-2026-96651","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"[0,1.43.3.10861)"}},{"platform":null,"status":"unaffected","versions":{"scheme":"generic","value":"1.43.3.10861"}}],"enrichment":{"confidence":100.0,"confidence_source":"matching","scores":[{"score":100.0,"source":"matching"}]},"original":{"product":"Media Server","source":"cna","vendor":"Plex"},"product":"media_server","vendor":"plex"}],"created":"2026-09-23T18:00:07.947378+00:00","updated":"2026-09-23T18:30:06.735694+00:00","vendors":["plex","plex$PRODUCT$media_server"]},"mitre":{"cpes":[],"created":"2026-09-23T16:06:00.176000+00:00","description":"Plex Media Server before 1.43.3.10861 builds a file path from the url parameter without checking it for ../ sequences, allowing path traversal via '/system/agents/media/get'. A remote attacker with a valid session token could read any file that the target user can access. This access includes the PlexOnlineToken, which grants control of the Plex account and server. A LAN-adjacent attacker with a client-supplied X-Forwarded-For header could exploit the same issue.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":6.5,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"cvssV4_0":{"score":7.1,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}},"mitre_repo_path":"cves/2026/96xxx/CVE-2026-96651.json","references":["https://forums.plex.tv/t/plex-media-server/30447/711","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-266-01.json","https://www.cve.org/CVERecord?id=CVE-2026-96651","https://zmain.info/blog/plex2shell"],"title":"Plex Media Server path traversal","updated":"2026-09-23T16:46:13.458000+00:00","vendors":[],"weaknesses":["CWE-22"]},"nvd":{"cpes":[],"created":"2026-09-23T17:17:23.187000+00:00","description":"Plex Media Server before 1.43.3.10861 builds a file path from the url parameter without checking it for ../ sequences, allowing path traversal via '/system/agents/media/get'. A remote attacker with a valid session token could read any file that the target user can access. This access includes the PlexOnlineToken, which grants control of the Plex account and server. A LAN-adjacent attacker with a client-supplied X-Forwarded-For header could exploit the same issue.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":6.5,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"cvssV4_0":{"score":7.1,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}},"nvd_repo_path":"2026/CVE-2026-96651.json","references":["https://forums.plex.tv/t/plex-media-server/30447/711","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-266-01.json","https://www.cve.org/CVERecord?id=CVE-2026-96651","https://zmain.info/blog/plex2shell"],"title":null,"updated":"2026-09-23T17:58:26.570000+00:00","vendors":[],"weaknesses":["CWE-22"]},"opencve":{"changes":[{"created":"2026-09-23T16:30:00+00:00","data":[{"details":{"new":"Plex Media Server before 1.43.3.10861 builds a file path from the url parameter without checking it for ../ sequences, allowing path traversal via '/system/agents/media/get'. A remote attacker with a valid session token could read any file that the target user can access. This access includes the PlexOnlineToken, which grants control of the Plex account and server. A LAN-adjacent attacker with a client-supplied X-Forwarded-For header could exploit the same issue.","old":null},"type":"description"},{"details":{"new":"Plex Media Server path traversal","old":null},"type":"title"},{"details":{"added":["CWE-22"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://forums.plex.tv/t/plex-media-server/30447/711","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-266-01.json","https://www.cve.org/CVERecord?id=CVE-2026-96651","https://zmain.info/blog/plex2shell"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":6.5,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"cvssV4_0":{"score":7.1,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"7f4383f8-5273-457e-985c-19b9d3f97f3e"},{"created":"2026-09-23T17:30:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"59f30350-5f4a-405c-bada-8311be65cb43"},{"created":"2026-09-23T18:45:00+00:00","data":[{"details":["plex","plex$PRODUCT$media_server"],"type":"first_time"},{"details":{"added":["plex","plex$PRODUCT$media_server"],"removed":[]},"type":"vendors"}],"id":"8ce933ab-218a-453e-a9c9-422ebf44fc9c"}],"cpes":{"data":[],"providers":[]},"created":{"data":"2026-09-23T16:06:00.176000+00:00","provider":"mitre"},"description":{"data":"Plex Media Server before 1.43.3.10861 builds a file path from the url parameter without checking it for ../ sequences, allowing path traversal via '/system/agents/media/get'. A remote attacker with a valid session token could read any file that the target user can access. This access includes the PlexOnlineToken, which grants control of the Plex account and server. A LAN-adjacent attacker with a client-supplied X-Forwarded-For header could exploit the same issue.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":6.5,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"provider":"mitre"},"cvssV4_0":{"data":{"score":7.1,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"},"provider":"mitre"},"epss":{"data":{},"provider":null},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://forums.plex.tv/t/plex-media-server/30447/711","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-266-01.json","https://www.cve.org/CVERecord?id=CVE-2026-96651","https://zmain.info/blog/plex2shell"],"providers":["mitre","nvd"]},"title":{"data":"Plex Media Server path traversal","provider":"mitre"},"updated":{"data":"2026-09-23T18:30:06.735694+00:00","provider":"enrichment"},"vendors":{"data":["plex","plex$PRODUCT$media_server"],"providers":["enrichment"]},"weaknesses":{"data":["CWE-22"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2026-09-23T16:06:00.176000+00:00","description":"Plex Media Server before 1.43.3.10861 builds a file path from the url parameter without checking it for ../ sequences, allowing path traversal via '/system/agents/media/get'. A remote attacker with a valid session token could read any file that the target user can access. This access includes the PlexOnlineToken, which grants control of the Plex account and server. A LAN-adjacent attacker with a client-supplied X-Forwarded-For header could exploit the same issue.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"references":[],"title":"Plex Media Server path traversal","updated":"2026-09-23T16:36:39.071000+00:00","vendors":[],"vulnrichment_repo_path":"2026/96xxx/CVE-2026-96651.json","weaknesses":[]}}