Path Traversal Vulnerability in Tautulli for Plex Media Server
CVE-2026-40605
5.7MEDIUM
What is CVE-2026-40605?
Tautulli, a monitoring tool for Plex Media Server, exhibits a path traversal vulnerability in its cache deletion endpoint. Prior to version 2.17.1, this vulnerability permits authenticated API users to delete directories beyond the configured cache path, leading to potential arbitrary data loss and disruption of services. The issue has been addressed in version 2.17.1, which enhances the security of the application.
Affected Version(s)
Tautulli < 2.17.1
