Stored XSS Vulnerability in Tautulli Monitoring Tool for Plex Media Server
CVE-2026-49995
4.8MEDIUM
What is CVE-2026-49995?
Tautulli, a monitoring and tracking tool for Plex Media Server, contains a vulnerability that allows stored cross-site scripting (XSS). Prior to version 2.17.2, an attacker with the Tautulli API key can inject a malicious configuration into the newsletter section of the application. This crafted cron value is then stored in the database without proper JSON encoding, which can lead to unintended script execution when an administrator accesses the configuration modal. The vulnerability persists even after credential changes, making it crucial to remove the malicious entry manually. This issue has been addressed in version 2.17.2 to enhance the security of Tautulli users.
Affected Version(s)
Tautulli < 2.17.2
