NONE · 0

CVE-2026-41065

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 are vulnerable to remote code execution via the newsletter custom template directory feature. On...

Vulnerability Description

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 are vulnerable to remote code execution via the newsletter custom template directory feature. On a fresh install before the setup wizard is completed, all management endpoints are completely unauthenticated. An attacker can create a newsletter agent, point the custom template directory to an attacker-controlled SMB share serving a malicious Mako template, and trigger execution via the newsletter render endpoint, all with zero credentials and no local access to the target system. On a completed install with credentials configured, the same chain is exploitable by any admin. Version 2.17.1 fixes the issue.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-41065?

CVE-2026-41065 is a documented vulnerability. Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 are vulnerable to remote code execution via the newsletter custom template directory feature. On...

How severe is CVE-2026-41065?

CVSS scoring is not yet available for CVE-2026-41065. Check NVD for updates.

Is there a patch for CVE-2026-41065?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.