Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.1, a path traversal vulnerability in the cache deletion endpoint allows authenticated API access to delete directories outside the configured cache path. This can cause arbitrary data loss and service disruption. Version 2.17.1 fixes the issue.
CVSS
No CVSS.
References
Configurations
No configuration.
History
04 Jun 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/Tautulli/Tautulli/security/advisories/GHSA-fg46-xx7h-mhwr - |
04 Jun 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-04 14:16
Updated : 2026-06-04 16:16
NVD link : CVE-2026-40605
Mitre link : CVE-2026-40605
CVE.ORG link : CVE-2026-40605
JSON object : View
Products Affected
No product.
