PT-2026-46257 · Tautulli · Tautulli

·

CVE-2026-43984

·

Published

2026-06-04

·

Updated

2026-06-04

CVSS v3.1

8.9

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Tautulli versions prior to 2.17.1
Description A stored cross-site scripting condition exists where authenticated users, including guests, can inject HTML or JavaScript into the main application log. This occurs because the log js errors endpoint writes attacker-controlled strings directly into the log file. When an administrator accesses the logFile view, the application embeds the log content into an HTML response without proper escaping, leading to the execution of the injected code in the administrator's browser.
Recommendations Update to version 2.17.1.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-43984
GHSA-F4J7-PJWC-4JRR

Affected Products

Tautulli