PT-2026-46228 · Plex+1 · Plex Media Server+1
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Tautulli versions prior to 2.17.1
Description
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. A path traversal issue in the cache deletion endpoint allows authenticated API access to delete directories outside the configured cache path, which can lead to arbitrary data loss and service disruption. Path traversal is a technique that allows an attacker to access files or directories outside the intended folder by using special characters like "../".
Recommendations
Update to version 2.17.1.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Plex Media Server
Tautulli