Stored XSS Vulnerability in Tautulli Monitoring Tool for Plex Media Server
CVE-2026-49995

4.8MEDIUM

Key Information:

Vendor

Tautulli

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-49995?

Tautulli, a monitoring and tracking tool for Plex Media Server, contains a vulnerability that allows stored cross-site scripting (XSS). Prior to version 2.17.2, an attacker with the Tautulli API key can inject a malicious configuration into the newsletter section of the application. This crafted cron value is then stored in the database without proper JSON encoding, which can lead to unintended script execution when an administrator accesses the configuration modal. The vulnerability persists even after credential changes, making it crucial to remove the malicious entry manually. This issue has been addressed in version 2.17.2 to enhance the security of Tautulli users.

Affected Version(s)

Tautulli < 2.17.2

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.