Server-Side Request Forgery Vulnerability in Tautulli Plex Monitoring Tool
CVE-2026-43986
9.9CRITICAL
What is CVE-2026-43986?
Tautulli, a monitoring and tracking tool for Plex Media Server, has a vulnerability that affects versions prior to 2.17.1. This vulnerability is due to the exposure of a public /image/<hash> route, which allows low-privilege guest users to exploit the system. By manipulating the image_hash_lookup table, an attacker can input a malicious external image URL. This vulnerability effectively turns a previously authenticated SSRF mechanism into a persistent threat accessible through an unauthenticated endpoint. Once the harmful entry is in place, users can request the /image/<hash>.png path, prompting the server to fetch content from an arbitrary, attacker-defined URL. The vulnerability has been addressed in version 2.17.1.
Affected Version(s)
Tautulli < 2.17.1
