HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-31831 — Tautulli is a Python based monitoring and tracking tool for Plex Media Server. P...

Monday, March 30, 2026 at 08:16 PM UTC·Source: NIST NVD

Updated: Monday, April 6, 2026 at 12:17 AM UTC

Executive Summary

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /newsletter/image/images API endpoint is vulnerable to path traversal, allowing unauthenticated attackers to read arbitrary files from the application server's filesystem. This issue has been patched in version 2.17.0.

Analysis

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /newsletter/image/images API endpoint is vulnerable to path traversal, allowing unauthenticated attackers to read arbitrary files from the application server's filesystem. This issue has been patched in version 2.17.0. CVSS Score: 7.5. Published: 2026-03-30T20:16:21.673.

Indicators of Compromise (1)

CVE (1)
CVE-2026-31831
Source Attribution

Originally published by NIST NVD on Mar 30, 2026. Verified by: NIST.

Related Threats