216.73.217.50

CVE-2026-31831

· Published 30/03/2026 20:16 · Modified 31/03/2026 20:16

Labels: CVE-2026-31831 2026-03-30CVE-2026-31831CWE-23[email protected]

Essential information

Published
30/03/2026 20:16
Modified
31/03/2026 20:16
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /newsletter/image/images API endpoint is vulnerable to path traversal, allowing unauthenticated attackers to read arbitrary files from the application server's filesystem. This issue has been patched in version 2.17.0.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
tautulli / tautulli cpe:2.3:a:tautulli:tautulli:<2.17.0:*:*:*:*:*:*:*

References