[{"data":1,"prerenderedAt":226},["ShallowReactive",2],{"seo-verification":3,"blog-plex-security-migration-jellyfin-navidrome-vps-en":6},{"google":4,"bing":5},"EycwPY2XMyTkVzas3n1ygeNJFGAH513qrMjfDljzsMQ","",{"key":7,"data":8},"blog-plex-security-migration-jellyfin-navidrome-vps-en",{"id":9,"slug":10,"slugs":11,"title":15,"excerpt":16,"readTime":17,"views":18,"isPinned":19,"publishedAt":20,"updatedAt":21,"category":22,"categories":28,"featuredImage":30,"bgImage":31,"posterImage":32,"relatedSolution":30,"intro":33,"sections":34,"ctaTitle":164,"ctaBody":165,"ctaButton":166,"ctaUrl":167,"relatedPosts":168},394,"plex-security-migration-jellyfin-navidrome-vps",{"fr":12,"en":10,"ar":13,"es":14},"plex-securite-migration-jellyfin-navidrome-vps","امان-plex-هجرة-jellyfin-navidrome-vps","seguridad-plex-migrar-jellyfin-navidrome-vps","Migrate Plex to Jellyfin and Navidrome on a VPS","36,000 Plex servers unpatched against CVE-2026-96656 and CVE-2026-96651. Complete guide to migrate video and music libraries to Jellyfin and Navidrome on a root VPS.",8,0,false,"2026-09-28T00:00:00+00:00","2026-09-29T14:40:42+00:00",{"id":23,"name":24,"slug":25,"color":26,"icon":27},7,"Self-hosting","self-hosting","bg-indigo-500\u002F10 text-indigo-400","cloud",[29],{"id":23,"name":24,"slug":25,"color":26,"icon":27},null,"\u002Fblog\u002Fcovers\u002Fbg.svg","\u002Fblog\u002Fcovers\u002Fplex-securite-migration-jellyfin-navidrome-vps-poster.svg","In September 2026, the Shadowserver Foundation counted over 36,000 internet-exposed Plex instances still running versions older than 1.43.3 — the release that patches two critical vulnerabilities enabling arbitrary file writes and directory traversal. If you self-host Plex on a root VPS, the exposure window is real and documented. This guide shows you how to switch to Jellyfin (video) and Navidrome (music) without losing your libraries, metadata, or playlists, and why the cost of migrating is lower than the risk of staying.",[35,39,42,50,53,56,83,86,100,103,147,150,153,158,161],{"type":36,"title":37,"body":38},"h2","Why leave Plex in 2026: 36,000 servers exposed","On September 9, 2026, Shadowserver published its findings: over 36,000 Plex servers accessible from the internet had not applied the 1.43.3 update, available since May 19. Two CVEs are at the core of this advisory. CVE-2026-96656 (CVSS 7.2) lets an admin-level attacker write arbitrary files that are executed on startup — concretely, load a malicious plugin that drops a rootkit, with no signature or execute-bit check. CVE-2026-96651 (CWE-22, path traversal) allows any authenticated session to read any file accessible to the Plex system user, including the PlexOnlineToken. Combined, these two flaws cover a full escalation scenario: session theft, then code execution. Plex patched both in build 1.43.3.10861; build 1.43.3.10896 is the recommended target. The structural problem remains: Plex is proprietary software whose patch cycle depends on a single vendor, and 36,000 administrators had not applied a four-month-old fix.",{"type":36,"title":40,"body":41},"What Plex hides behind its cloud model","Plex offers a polished interface, but its cloud model introduces hidden dependencies that become problematic in the event of a security patch or service discontinuation.",{"type":43,"items":44},"ul",[45,46,47,48,49],"Remote access via Plex Relay: every stream goes through plex.tv servers, even if your VPS is the only one storing the files. Plex sees your playback metadata.","Plex Pass required for key features: offline sync, full multi-user access, Live TV, and remote access without port forwarding are reserved for paying subscribers.","Centralized authentication: your clients' logins go through Plex servers. A plex.tv outage locks you out of your own files.","Uncontrolled updates: Plex can deploy server-side changes (relay, authentication) without you being able to audit or block them.","Active telemetry by default: playback, searches, and viewing habits are sent to the vendor unless manually disabled in each client.",{"type":36,"title":51,"body":52},"Prerequisites before starting the migration","This procedure targets a root VPS running Debian 12 or Ubuntu 22.04 LTS. You need SSH root or sudo access, Docker and Docker Compose installed (v2+), and a media directory accessible for reading. Take a VPS snapshot before starting — snapshots are reversible in one command and cost less than an hour of compute. Jellyfin replaces the video library; Navidrome replaces the music library. Both are open source, subscription-free, and exposed behind an Nginx reverse proxy.",{"type":36,"title":54,"body":55},"Plex → Jellyfin migration: step-by-step","Here is the complete procedure for migrating your Plex library to Jellyfin without losing your data or watch history.",{"type":57,"steps":58},"steps",[59,62,65,68,71,74,77,80],{"title":60,"body":61},"Create a VPS snapshot","First: `snapshot create plex-before-migration` from your provider's panel (or equivalent API). This step is your safety net; do not skip it.",{"title":63,"body":64},"Stop Plex cleanly","```bash\nsystemctl stop plexmediaserver\nsystemctl disable plexmediaserver\n```\nWait for the shutdown confirmation before continuing. Plex must no longer be listening on port 32400.",{"title":66,"body":67},"Install Jellyfin via Docker Compose","```yaml\n# \u002Fopt\u002Fjellyfin\u002Fdocker-compose.yml\nservices:\n  jellyfin:\n    image: jellyfin\u002Fjellyfin:latest\n    container_name: jellyfin\n    restart: unless-stopped\n    ports:\n      - \"8096:8096\"\n    volumes:\n      - \u002Fopt\u002Fjellyfin\u002Fconfig:\u002Fconfig\n      - \u002Fopt\u002Fjellyfin\u002Fcache:\u002Fcache\n      - \u002Fdata\u002Fmedia:\u002Fmedia:ro\n    environment:\n      - JELLYFIN_PublishedServerUrl=https:\u002F\u002Fjellyfin.your-domain.com\n```\nReplace `\u002Fdata\u002Fmedia` with the exact path to your media files. The volume is mounted read-only (`:ro`) as a precaution.",{"title":69,"body":70},"Start Jellyfin and run the setup wizard","```bash\ncd \u002Fopt\u002Fjellyfin && docker compose up -d\n```\nAccess `http:\u002F\u002FVPS-IP:8096` for the web wizard. Create the admin account, then add your libraries pointing to `\u002Fmedia\u002Ffilms`, `\u002Fmedia\u002Fseries`, etc.",{"title":72,"body":73},"Scan libraries and verify metadata","Jellyfin uses The Movie Database (TMDB) and TheTVDB by default. The first full scan takes between 5 and 30 minutes depending on library size. Verify that covers, synopses, and ratings display correctly. If a title is not automatically recognized, use the Identify function to force the match.",{"title":75,"body":76},"Configure Jellyfin clients","Official Jellyfin apps are available on Android, iOS, Apple TV, Android TV, Roku, and browsers. They are free and open source. Point each client to your server's internal or public URL — no third-party authentication required.",{"title":78,"body":79},"Verify transcoding and subtitles","In Dashboard > Playback, enable hardware transcoding if your VPS has a GPU (Intel Quick Sync, NVIDIA NVENC). Test an H.265 file from a mobile client to validate that software transcoding works as fallback. Also verify that SRT and ASS\u002FSSA subtitles display correctly.",{"title":81,"body":82},"Remove Plex","```bash\napt remove plexmediaserver --purge\nrm -rf \u002Fvar\u002Flib\u002Fplexmediaserver\n```\nOnly remove the old installation after validating Jellyfin on at least one client for 48 hours.",{"type":36,"title":84,"body":85},"Music migration: Plex → Navidrome","Navidrome is an open source music server compatible with the Subsonic API, giving it access to the entire client ecosystem (DSub, Symfonium, Ultrasonic, Airsonic, etc.). It reads ID3 v2.3 and v2.4 tags, FLAC, MP3, AAC, OGG, and Opus files. M3U playlists present in your music directory are imported automatically, provided paths are relative to the music root.",{"type":57,"steps":87},[88,91,94,97],{"title":89,"body":90},"Check folder structure","Navidrome expects an `Artist\u002FAlbum\u002FTrack.mp3` hierarchy. If your files are already organized this way (which Plex also requires), no reorganization is needed. Check for special characters in folder names (`\u002F`, `:`, `?`).",{"title":92,"body":93},"Audit ID3 tags","```bash\nfind \u002Fdata\u002Fmusic -name '*.mp3' | head -20 | xargs id3v2 -l\n```\nFields `TPE1` (artist), `TALB` (album), and `TIT2` (title) must be filled in. A file without these three tags will be imported but with no displayable metadata. The `beets` tool can fix missing tags in bulk via its MusicBrainz database.",{"title":95,"body":96},"Deploy Navidrome via Docker Compose","```yaml\n# \u002Fopt\u002Fnavidrome\u002Fdocker-compose.yml\nservices:\n  navidrome:\n    image: deluan\u002Fnavidrome:latest\n    container_name: navidrome\n    restart: unless-stopped\n    ports:\n      - \"4533:4533\"\n    volumes:\n      - \u002Fopt\u002Fnavidrome\u002Fdata:\u002Fdata\n      - \u002Fdata\u002Fmusic:\u002Fmusic:ro\n    environment:\n      - ND_SCANSCHEDULE=1h\n      - ND_LOGLEVEL=info\n      - ND_BASEURL=\n```\nStart with `docker compose up -d` then access `http:\u002F\u002FIP:4533` to create the first account.",{"title":98,"body":99},"Migrate Plex playlists","Plex does not natively export playlists in M3U format from the interface. Use the `plexapi` Python tool to export: `python3 -m plexapi.playlist export --token YOUR_TOKEN --output \u002Fdata\u002Fmusic\u002Fplaylists\u002F`. The generated M3U files are automatically imported by Navidrome if paths are relative to the `\u002Fmusic` volume.",{"type":36,"title":101,"body":102},"Plex vs Jellyfin vs Navidrome comparison","The following table compares the essential criteria for choosing between Plex, Jellyfin, and Navidrome.",{"type":104,"headers":105,"rows":110},"comparison",[106,107,108,109],"Criterion","Plex","Jellyfin","Navidrome",[111,116,120,124,128,133,138,143],[112,113,114,115],"License","Proprietary (freemium)","GPL-2.0 open source","GPL-3.0 open source",[117,118,119,119],"Remote access without subscription","No (Plex Pass required)","Yes, native",[121,122,123,123],"Third-party authentication required","Yes (plex.tv)","No",[125,126,126,127],"Video library","Yes","No (music only)",[129,130,131,132],"Music library","Yes (limited)","Partial","Yes (specialized)",[134,135,136,137],"Hardware transcoding","Plex Pass required","Native (NVENC, QSV, VAAPI)","N\u002FA (audio only)",[139,140,141,142],"Official mobile clients","Paid on iOS\u002FAndroid","Free, open source","Third-party Subsonic clients",[144,145,146,146],"Cloud dependency","Strong (relay, auth)","None",{"type":36,"title":148,"body":149},"Nginx reverse proxy configuration for Jellyfin","Jellyfin must be exposed via HTTPS. The configuration below assumes a Let's Encrypt certificate managed by Certbot or your CDN in Full (strict) mode. Never expose port 8096 directly — always go through Nginx.\n\n```nginx\n# \u002Fetc\u002Fnginx\u002Fsites-available\u002Fjellyfin\nserver {\n    listen 80;\n    server_name jellyfin.your-domain.com;\n    return 301 https:\u002F\u002F$host$request_uri;\n}\n\nserver {\n    listen 443 ssl http2;\n    server_name jellyfin.your-domain.com;\n\n    ssl_certificate \u002Fetc\u002Fletsencrypt\u002Flive\u002Fjellyfin.your-domain.com\u002Ffullchain.pem;\n    ssl_certificate_key \u002Fetc\u002Fletsencrypt\u002Flive\u002Fjellyfin.your-domain.com\u002Fprivkey.pem;\n\n    add_header X-Frame-Options \"SAMEORIGIN\";\n    add_header X-Content-Type-Options \"nosniff\";\n    add_header X-XSS-Protection \"1; mode=block\";\n\n    location \u002F {\n        proxy_pass http:\u002F\u002F127.0.0.1:8096;\n        proxy_set_header Host $host;\n        proxy_set_header X-Real-IP $remote_addr;\n        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;\n        proxy_set_header X-Forwarded-Proto $scheme;\n\n        proxy_http_version 1.1;\n        proxy_set_header Upgrade $http_upgrade;\n        proxy_set_header Connection \"upgrade\";\n\n        proxy_buffering off;\n        proxy_read_timeout 3600;\n    }\n}\n```\nApply the same structure for Navidrome, replacing the port with 4533. Activate the config with `nginx -t && systemctl reload nginx`.",{"type":36,"title":151,"body":152},"Troubleshooting: the 3 most common migration errors","Here are the three most common problems during a Plex\u002FJellyfin migration, with their direct solutions.",{"type":43,"items":154},[155,156,157],"Library empty after first scan: verify that the Docker-mounted path exactly matches the directory containing your files. `docker exec jellyfin ls \u002Fmedia` should list your folders. If the volume is empty, fix the mapping in docker-compose.yml and restart the container.","Transcoding fails with ffmpeg error: Jellyfin ships its own version of ffmpeg. If the container has no GPU access, disable hardware transcoding in Dashboard > Playback and switch to software transcoding. On a VPS without a GPU, this is the normal configuration.","iOS\u002FAndroid clients cannot find the server: make sure the firewall allows port 443 from outside (`ufw allow 443`), your DNS points to the VPS IP, and the TLS certificate is valid. Test with `curl -I https:\u002F\u002Fjellyfin.your-domain.com\u002Fhealth` from your local machine.",{"type":159,"body":160},"tip","Keep Plex disabled (not uninstalled) for the first 48 hours after migration. The VPS snapshot lets you roll back in under five minutes. Only delete Plex config files (`\u002Fvar\u002Flib\u002Fplexmediaserver`) after confirming all your clients work correctly on Jellyfin and Navidrome.",{"type":36,"title":162,"body":163},"Conclusion","36,000 unpatched Plex servers are not a sign of individual negligence: they reveal a structural dependency on a proprietary vendor whose patch cycle is opaque. CVE-2026-96656 and CVE-2026-96651 show that this dependency has a measurable cost. Jellyfin and Navidrome give you back control: no third-party authentication, no cloud relay, no subscription for remote access. The migration takes under an hour with this guide; the library is intact on arrival. If you host your media on a root VPS, there is no longer any reason to wait.","Host Jellyfin on a root VPS today","ServOrbit offers Jellyfin preconfigured on a root VPS starting at 99 DH\u002Fmonth. One-click deployment, Nginx reverse proxy included, no subscription or third-party cloud.","Deploy Jellyfin on VPS","\u002Fmarketplace\u002Fmedia\u002Fjellyfin",[169,189,208],{"id":170,"slug":171,"slugs":172,"title":176,"excerpt":177,"readTime":178,"views":179,"isPinned":19,"publishedAt":180,"updatedAt":181,"category":182,"categories":183,"featuredImage":30,"bgImage":31,"posterImage":185,"relatedSolution":186},84,"host-jellyfin-on-your-own-vps",{"fr":173,"en":171,"ar":174,"es":175},"heberger-jellyfin","استضافة-jellyfin-على-خادمك-الافتراضي-الخاص-vps","alojar-jellyfin-en-un-vps","Self-Hosting Jellyfin on a VPS: Complete 2026 Guide","Deploy Jellyfin on your own VPS with Docker, nginx, HTTPS, plugins, storage options and hardware transcoding. Full guide updated for 2026.",10,3,"2026-03-28T00:00:00+00:00","2026-09-07T11:26:10+00:00",{"id":23,"name":24,"slug":25,"color":26,"icon":27},[184],{"id":23,"name":24,"slug":25,"color":26,"icon":27},"\u002Fblog\u002Fcovers\u002Fheberger-jellyfin-poster.svg",{"categorySlug":187,"appSlug":188},"collaboration-productivity","jellyfin",{"id":190,"slug":191,"slugs":192,"title":196,"excerpt":197,"readTime":17,"views":18,"isPinned":19,"publishedAt":198,"updatedAt":199,"category":200,"categories":205,"featuredImage":30,"bgImage":31,"posterImage":207,"relatedSolution":30},98,"jellyfin-vs-plex-which-self-hosted-media-server",{"fr":193,"en":191,"ar":194,"es":195},"jellyfin-vs-plex","jellyfin-مقابل-plex-أي-خادم-وسائط-مستضاف-ذاتيا","jellyfin-vs-plex-que-servidor-multimedia-autoalojado","Jellyfin vs Plex: Which Self-Hosted Media Server?","Jellyfin vs Plex: complete comparison to choose your self-hosted media server on a VPS — Docker deployment, troubleshooting, and Jellyfin 12 migration.","2026-03-14T00:00:00+00:00","2026-09-10T13:10:43+00:00",{"id":201,"name":202,"slug":203,"color":204,"icon":203},5,"Comparison","comparatif","bg-info\u002F10 text-info",[206],{"id":201,"name":202,"slug":203,"color":204,"icon":203},"\u002Fblog\u002Fcovers\u002Fjellyfin-vs-plex-poster.svg",{"id":209,"slug":210,"slugs":211,"title":215,"excerpt":216,"readTime":178,"views":18,"isPinned":19,"publishedAt":217,"updatedAt":21,"category":218,"categories":223,"featuredImage":30,"bgImage":31,"posterImage":225,"relatedSolution":30},382,"vps-automatic-security-updates-debian-ubuntu",{"fr":212,"en":210,"ar":213,"es":214},"securite-vps-mises-a-jour-automatiques-debian-ubuntu","تحديثات-أمان-تلقائية-vps-debian-ubuntu","actualizaciones-seguridad-vps-debian-ubuntu","Automatic Security Updates on Debian\u002FUbuntu VPS","Configure unattended-upgrades on your Debian\u002FUbuntu VPS to automate security patches and reduce attack surface across your client fleet.","2026-09-26T00:00:00+00:00",{"id":17,"name":219,"slug":220,"color":221,"icon":222},"Security & Monitoring","securite-monitoring","bg-rose-500\u002F10 text-rose-400","security",[224],{"id":17,"name":219,"slug":220,"color":221,"icon":222},"\u002Fblog\u002Fcovers\u002Fsecurite-vps-mises-a-jour-automatiques-debian-ubuntu-poster.svg",1790693272916]