Server-Side Request Forgery Vulnerability in Tautulli Plex Monitoring Tool
CVE-2026-43986

9.9CRITICAL

Key Information:

Vendor

Tautulli

Status
Vendor
CVE Published:
4 June 2026

What is CVE-2026-43986?

Tautulli, a monitoring and tracking tool for Plex Media Server, has a vulnerability that affects versions prior to 2.17.1. This vulnerability is due to the exposure of a public /image/<hash> route, which allows low-privilege guest users to exploit the system. By manipulating the image_hash_lookup table, an attacker can input a malicious external image URL. This vulnerability effectively turns a previously authenticated SSRF mechanism into a persistent threat accessible through an unauthenticated endpoint. Once the harmful entry is in place, users can request the /image/<hash>.png path, prompting the server to fetch content from an arbitrary, attacker-defined URL. The vulnerability has been addressed in version 2.17.1.

Affected Version(s)

Tautulli < 2.17.1

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.