PT-2026-96231 · Tautulli · Tautulli

CVE-2026-54915

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Tautulli versions prior to 2.17.2
Description The unauthenticated '/auth/redirect' endpoint in plexpy/webauth.py fails to properly sanitize the redirect uri parameter. While forward slashes are removed, tab, line-feed, and carriage-return characters remain. When using the default root HTTP ROOT configuration, CherryPy HTTPRedirect passes this value to urllib.parse.urljoin, allowing the whitespace characters to resolve the path to an external origin controlled by an attacker. This can lead to phishing or post-login redirect-flow abuse if a user follows a crafted link. Custom non-root HTTP ROOT configurations are not affected.
Recommendations Update to version 2.17.2.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54915
GHSA-7C9R-FHJ9-87XM

Affected Products

Tautulli