CVE-2026-40605
Tautulli Vulnerable to Authenticated Path Traversal in Cache Deletion API
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.1, a path traversal vulnerability in the cache deletion endpoint allows authenticated API access to delete directories outside the configured cache path. This can cause arbitrary data loss and service disruption. Version 2.17.1 fixes the issue.
| CWE | CWE-22 CWE-73 |
| Vendor | tautulli |
| Product | tautulli |
| Published | Jun 4, 2026 |
| Last Updated | Jun 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for tautulli tautulli
Be the first to know when new unknown vulnerabilities affecting tautulli tautulli are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Tautulli / Tautulli
< 2.17.1