CVE-2026-31831 HIGH

CVE-2026-31831: Tautulli: Unauthenticated Path Traversal in `/newsletter/image/images` endpoint

Vendor Tautulli
Product Tautulli
Weakness CWE-23
Published March 30, 2026
Last update March 31, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /newsletter/image/images API endpoint is vulnerable to path traversal, allowing unauthenticated attackers to read arbitrary files from the application server's filesystem. This issue has been patched in version 2.17.0.

Key dates

02Disclosure timeline

March 30, 2026 CVE published
March 31, 2026 Record updated