Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.1, a path traversal vulnerability in the cache deletion endpoint allows authenticated API access to delete directories outside the configured cache path. This can cause arbitrary data loss and service disruption. Version 2.17.1 fixes the issue.
Metrics
Affected Vendors & Products
References
History
Thu, 04 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.1, a path traversal vulnerability in the cache deletion endpoint allows authenticated API access to delete directories outside the configured cache path. This can cause arbitrary data loss and service disruption. Version 2.17.1 fixes the issue. | |
| Title | Tautulli Vulnerable to Authenticated Path Traversal in Cache Deletion API | |
| Weaknesses | CWE-22 CWE-73 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-04T12:50:10.079Z
Reserved: 2026-04-14T14:07:59.642Z
Link: CVE-2026-40605
No data.
Status : Received
Published: 2026-06-04T14:16:40.520
Modified: 2026-06-04T14:16:40.520
Link: CVE-2026-40605
No data.
OpenCVE Enrichment
No data.