---
id: CVE-2026-96656
title: >-
  Plex Media Server before 1.43.3.10861 allows an admin user to write arbitrary
  files that may be executed on load
summary: >-
  Plex Media Server before 1.43.3.10861 allows an admin user to write arbitrary
  files that may be executed on load. The preference TranscoderH264Options is
  appended verbatim to x264's option string on every transcode. At startup, all
  .so f…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-73
vendor: Plex
product: Media Server
affected:
  - media_server < 1.43.3.10861
published: '2026-09-23'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T17:58:26.570'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-96656'
references:
  - url: 'https://forums.plex.tv/t/plex-media-server/30447/711'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-266-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-96656'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: 'https://zmain.info/blog/plex2shell'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-23T16:35:05.105006Z'
ingestedAt: '2026-09-23T16:27:22.663Z'
epss: 0.00339
epssPercentile: 0.24649
---

## Overview

Plex Media Server before 1.43.3.10861 allows an admin user to write arbitrary files that may be executed on load. The preference TranscoderH264Options is appended verbatim to x264's option string on every transcode. At startup, all .so files are run without signature, execute bit, or symbol checks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
