Vulnerability Description
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.1, a path traversal vulnerability in the cache deletion endpoint allows authenticated API access to delete directories outside the configured cache path. This can cause arbitrary data loss and service disruption. Version 2.17.1 fixes the issue.
Related Weaknesses (CWE)
References
- https://github.com/Tautulli/Tautulli/releases/tag/v2.17.1
- https://github.com/Tautulli/Tautulli/security/advisories/GHSA-fg46-xx7h-mhwr
- https://github.com/Tautulli/Tautulli/security/advisories/GHSA-fg46-xx7h-mhwr
FAQ
What is CVE-2026-40605?
CVE-2026-40605 is a documented vulnerability. Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.1, a path traversal vulnerability in the cache deletion endpoint allows authenticated API access to...
How severe is CVE-2026-40605?
CVSS scoring is not yet available for CVE-2026-40605. Check NVD for updates.
Is there a patch for CVE-2026-40605?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.