Vulnerability in Tautulli Affects Plex Media Server
CVE-2026-54915

5.4MEDIUM

Key Information:

Vendor

Tautulli

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-54915?

Tautulli, a monitoring and tracking tool for Plex Media Server, has a vulnerability that allows unauthenticated access to its /auth/redirect endpoint. In versions prior to 2.17.2, this vulnerability allows an attacker to manipulate the redirect_uri parameter. While the endpoint removes forward slashes, it does not address whitespace characters such as tabs and line feeds. This oversight can lead to users being redirected to fraudulent external sites, posing a risk for phishing attacks or misuse of post-login flows. This risk primarily affects installations using the default HTTP_ROOT configuration, while custom configurations may avoid this issue. The vulnerability was resolved in version 2.17.2.

Affected Version(s)

Tautulli < 2.17.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.