Tautulli Vulnerable to Authenticated Path Traversal in Cache Deletion API
CVE-2026-40605

5.7MEDIUM

Key Information:

Vendor

Tautulli

Status
Vendor
CVE Published:
4 June 2026

What is CVE-2026-40605?

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.1, a path traversal vulnerability in the cache deletion endpoint allows authenticated API access to delete directories outside the configured cache path. This can cause arbitrary data loss and service disruption. Version 2.17.1 fixes the issue.

Affected Version(s)

Tautulli < 2.17.1

References

CVSS V4

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.