PT-2026-96229 · Plex+1 · Plex Media Server+1
CVE-2026-49995
·
Published
2026-09-21
·
Updated
2026-09-22
CVSS v4.0
4.8
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Tautulli versions prior to 2.17.2
Description
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. The application fails to use safe JSON encoding when inserting the newsletter cron field from the
newsletters table into a JavaScript string within data/interfaces/default/newsletter config.html. An attacker with an API key or administrator privileges can store a malicious cron value. When an administrator opens the newsletter configuration modal, the script executes in the web context. This stored value remains in the database and persists even after credentials are rotated.Recommendations
Update to version 2.17.2.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plex Media Server
Tautulli