Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.1, a path traversal vulnerability in the cache deletion endpoint allows authenticated API access to delete directories outside the configured cache path. This can cause arbitrary data loss and service disruption. Version 2.17.1 fixes the issue.
Metrics
Affected Vendors & Products
References
History
Thu, 04 Jun 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tautulli
Tautulli tautulli |
|
| Vendors & Products |
Tautulli
Tautulli tautulli |
|
| Metrics |
ssvc
|
Thu, 04 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.1, a path traversal vulnerability in the cache deletion endpoint allows authenticated API access to delete directories outside the configured cache path. This can cause arbitrary data loss and service disruption. Version 2.17.1 fixes the issue. | |
| Title | Tautulli Vulnerable to Authenticated Path Traversal in Cache Deletion API | |
| Weaknesses | CWE-22 CWE-73 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-04T15:06:37.640Z
Reserved: 2026-04-14T14:07:59.642Z
Link: CVE-2026-40605
Updated: 2026-06-04T15:02:38.392Z
Status : Deferred
Published: 2026-06-04T14:16:40.520
Modified: 2026-06-04T16:16:36.437
Link: CVE-2026-40605
No data.
OpenCVE Enrichment
Updated: 2026-06-04T15:00:15Z