PT-2026-28789 · Tautulli+1 · Tautulli+1

Mandreko

·

Published

2026-03-28

·

Updated

2026-03-31

·

CVE-2026-31804

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Tautulli versions prior to 2.17.0
Description Tautulli is a Python-based monitoring and tracking tool for Plex Media Server. The /pms image proxy API endpoint accepts a user-supplied img parameter and forwards it to Plex Media Server’s /photo/:/transcode transcoder without authentication or scheme/host restriction. This endpoint is intentionally excluded from authentication checks. Any value of img starting with http is passed directly to Plex, causing the Plex Media Server process to make an outbound HTTP request to a URL specified by an attacker. The img parameter is vulnerable.
Recommendations Update Tautulli to version 2.17.0 or later.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-31804
GHSA-QJ2F-4C4P-WV97

Affected Products

Plex Media Server
Tautulli