Vulnerability in Tautulli Affects Plex Media Server
CVE-2026-54915
5.4MEDIUM
What is CVE-2026-54915?
Tautulli, a monitoring and tracking tool for Plex Media Server, has a vulnerability that allows unauthenticated access to its /auth/redirect endpoint. In versions prior to 2.17.2, this vulnerability allows an attacker to manipulate the redirect_uri parameter. While the endpoint removes forward slashes, it does not address whitespace characters such as tabs and line feeds. This oversight can lead to users being redirected to fraudulent external sites, posing a risk for phishing attacks or misuse of post-login flows. This risk primarily affects installations using the default HTTP_ROOT configuration, while custom configurations may avoid this issue. The vulnerability was resolved in version 2.17.2.
Affected Version(s)
Tautulli < 2.17.2
