CVE 8.9 HIGH

Tautulli Vulnerable to Unauthenticated/Authenticated Remote Code Execution via Newsletter Custom Template Directory_CVE-2026-41065

8.9 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P

Description

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 are vulnerable to remote code execution via the newsletter custom template directory feature. On a fresh install before the setup wizard is completed, all management endpoints are completely unauthenticated. An attacker can create a newsletter agent, point the custom template directory to an attacker-controlled SMB share serving a malicious Mako template, and trigger execution via the newsletter render endpoint, all with zero credentials and no local access to the target system. On a completed install with credentials configured, the same chain is exploitable by any admin. Version 2.17.1 fixes the issue.

AI Analysis

Remote code execution via newsletter custom template directory

Basic Information

ID CVE-2026-41065
Source GitHub_M
Published Jun 4, 2026 at 14:17

Affected Product

Vendor Tautulli
Product Tautulli
Version < 2.17.1
Affected Versions Tautulli Tautulli < 2.17.1

CWE Classification

AI Assessment

AI Score 8.9 / 10
AI Severity High
Vendor Tautulli
Product Tautulli
Version < 2.17.1

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.