PT-2026-28789 · Tautulli+1 · Tautulli+1
Mandreko
·
Published
2026-03-28
·
Updated
2026-03-31
·
CVE-2026-31804
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Tautulli versions prior to 2.17.0
Description
Tautulli is a Python-based monitoring and tracking tool for Plex Media Server. The
/pms image proxy API endpoint accepts a user-supplied img parameter and forwards it to Plex Media Server’s /photo/:/transcode transcoder without authentication or scheme/host restriction. This endpoint is intentionally excluded from authentication checks. Any value of img starting with http is passed directly to Plex, causing the Plex Media Server process to make an outbound HTTP request to a URL specified by an attacker. The img parameter is vulnerable.Recommendations
Update Tautulli to version 2.17.0 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plex Media Server
Tautulli