Path Traversal Vulnerability in Tautulli Monitoring Tool for Plex Media Server
CVE-2026-31831
8.7HIGH
What is CVE-2026-31831?
Tautulli, a Python-based monitoring and tracking tool for Plex Media Server, contains a vulnerability in the /newsletter/image/images API endpoint that permits path traversal. This security flaw enables unauthenticated attackers to access and read arbitrary files from the server's filesystem. This issue was addressed and mitigated in version 2.17.0 of Tautulli, emphasizing the importance of maintaining updated software to protect against potential exploits.
Affected Version(s)
Tautulli < 2.17.0
