PT-2026-46248 · Plex+1 · Plex Media Server+1

Remindsec

·

Published

2026-06-04

·

Updated

2026-06-04

·

CVE-2026-41065

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Tautulli versions prior to 2.17.1
Description Tautulli is a Python-based monitoring and tracking tool for Plex Media Server. The software allows remote code execution through the newsletter custom template directory feature. In a fresh installation where the setup wizard is not yet completed, all management endpoints are unauthenticated. An attacker can create a newsletter agent, direct the custom template directory to an attacker-controlled SMB share containing a malicious Mako template (a template library for Python), and trigger execution via the newsletter render endpoint without credentials or local access. In installations where credentials have been configured, this sequence can be exploited by any administrator.
Recommendations Update to version 2.17.1.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2026-41065

Affected Products

Plex Media Server
Tautulli