CVE-2026-31831: Tautulli: Unauthenticated Path Traversal in `/newsletter/image/images` endpoint
Published Mar 30, 2026
·Updated
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /newsletter/image/images API endpoint is vulnerable to path traversal, allowing unauthenticated attackers to read arbitrary files from the application server's filesystem. This issue has been patched in version 2.17.0.
Affected Software
2 affected components
Tautulli Tautulli<2.17.0
Tautulli Tautulli<2.17.0
Event History
Mar 30, 2026
CVE Published
via MITRE·07:42 PM
Data Sourced
via MITRE·07:42 PM
DescriptionWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-31831?
CVE-2026-31831 has a high severity rating due to its potential for unauthenticated path traversal attacks.
2
How do I fix CVE-2026-31831?
To fix CVE-2026-31831, upgrade Tautulli to version 2.17.0 or later.
3
What is the impact of CVE-2026-31831?
The impact of CVE-2026-31831 allows unauthenticated attackers to read sensitive files on the server.
4
Which versions of Tautulli are affected by CVE-2026-31831?
Tautulli versions prior to 2.17.0 are affected by CVE-2026-31831.
5
Is authentication required to exploit CVE-2026-31831?
No, CVE-2026-31831 can be exploited without authentication.