๐Ÿ” CVE Alert

CVE-2026-40605

UNKNOWN 0.0

Tautulli Vulnerable to Authenticated Path Traversal in Cache Deletion API

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.1, a path traversal vulnerability in the cache deletion endpoint allows authenticated API access to delete directories outside the configured cache path. This can cause arbitrary data loss and service disruption. Version 2.17.1 fixes the issue.

CWE CWE-22 CWE-73
Vendor tautulli
Product tautulli
Published Jun 4, 2026
Last Updated Jun 4, 2026
Stay Ahead of the Next One

Get instant alerts for tautulli tautulli

Be the first to know when new unknown vulnerabilities affecting tautulli tautulli are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Tautulli / Tautulli
< 2.17.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Tautulli/Tautulli/security/advisories/GHSA-fg46-xx7h-mhwr github.com: https://github.com/Tautulli/Tautulli/releases/tag/v2.17.1