CVE-2026-32275: Tautulli: Unsanitized JSONP callback parameter allows cross-origin script injection and API key theft
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 1.3.10 to before version 2.17.0, an unsanitized JSONP callback parameter allows cross-origin script injection and API key theft. This issue has been patched in version 2.17.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32275?
CVE-2026-32275 has been classified as a moderate severity vulnerability due to its potential for cross-origin script injection and API key theft.
How do I fix CVE-2026-32275?
To resolve CVE-2026-32275, upgrade Tautulli to version 2.17.0 or later, where the vulnerability is addressed.
What systems are affected by CVE-2026-32275?
CVE-2026-32275 affects Tautulli versions from 1.3.10 to before 2.17.0.
What type of vulnerability is CVE-2026-32275?
CVE-2026-32275 is a cross-origin script injection vulnerability stemming from an unsanitized JSONP callback parameter.
Can CVE-2026-32275 lead to data theft?
Yes, CVE-2026-32275 can potentially lead to API key theft, which may expose sensitive data.