PT-2026-46228 · Plex+1 · Plex Media Server+1

·

CVE-2026-40605

·

Published

2026-06-04

·

Updated

2026-06-04

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Tautulli versions prior to 2.17.1
Description Tautulli is a Python based monitoring and tracking tool for Plex Media Server. A path traversal issue in the cache deletion endpoint allows authenticated API access to delete directories outside the configured cache path, which can lead to arbitrary data loss and service disruption. Path traversal is a technique that allows an attacker to access files or directories outside the intended folder by using special characters like "../".
Recommendations Update to version 2.17.1.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40605
GHSA-FG46-XX7H-MHWR

Affected Products

Plex Media Server
Tautulli