PT-2026-96230 · Tautulli · Tautulli

CVE-2026-52835

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v4.0

7.0

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Tautulli versions prior to 2.17.2
Description The import config handler and the database file branch of import database in plexpy/webserve.py join the config file.filename or database file.filename variables directly to CACHE DIR without performing basename reduction or a containment check. An administrator or a caller possessing the instance API key can submit a multipart filename containing parent-directory segments. This allows files to be created or overwritten outside the CACHE DIR before file-content validation occurs. While the write operation is limited to paths accessible by the Tautulli process, this can lead to configuration tampering, service disruption, or code execution.
Recommendations Update to version 2.17.2.

Exploit

Fix

Path traversal

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52835
GHSA-8WW5-PP25-3JM8

Affected Products

Tautulli