PT-2026-96229 · Plex+1 · Plex Media Server+1

CVE-2026-49995

·

Published

2026-09-21

·

Updated

2026-09-22

CVSS v4.0

4.8

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Tautulli versions prior to 2.17.2
Description Tautulli is a Python based monitoring and tracking tool for Plex Media Server. The application fails to use safe JSON encoding when inserting the newsletter cron field from the newsletters table into a JavaScript string within data/interfaces/default/newsletter config.html. An attacker with an API key or administrator privileges can store a malicious cron value. When an administrator opens the newsletter configuration modal, the script executes in the web context. This stored value remains in the database and persists even after credentials are rotated.
Recommendations Update to version 2.17.2.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49995
GHSA-R6PG-VQXJ-V75J

Affected Products

Plex Media Server
Tautulli