PT-2026-96230 · Tautulli · Tautulli
CVE-2026-52835
·
Published
2026-09-21
·
Updated
2026-09-21
CVSS v4.0
7.0
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Tautulli versions prior to 2.17.2
Description
The
import config handler and the database file branch of import database in plexpy/webserve.py join the config file.filename or database file.filename variables directly to CACHE DIR without performing basename reduction or a containment check. An administrator or a caller possessing the instance API key can submit a multipart filename containing parent-directory segments. This allows files to be created or overwritten outside the CACHE DIR before file-content validation occurs. While the write operation is limited to paths accessible by the Tautulli process, this can lead to configuration tampering, service disruption, or code execution.Recommendations
Update to version 2.17.2.
Exploit
Fix
Path traversal
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tautulli