CVE-2026-40605: Tautulli Vulnerable to Authenticated Path Traversal in Cache Deletion API
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.1, a path traversal vulnerability in the cache deletion endpoint allows authenticated API access to delete directories outside the configured cache path. This can cause arbitrary data loss and service disruption. Version 2.17.1 fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tautullito a version that resolves this vulnerability.Fixed in 2.17.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40605?
CVE-2026-40605 has a medium severity rating of 5.7.
How do I fix CVE-2026-40605?
To fix CVE-2026-40605, upgrade to Tautulli version 2.17.1 or later.
What type of vulnerability is CVE-2026-40605?
CVE-2026-40605 is a path traversal vulnerability.
What can happen if CVE-2026-40605 is exploited?
Exploitation of CVE-2026-40605 can lead to arbitrary data loss by deleting directories outside the configured cache path.
Who is affected by CVE-2026-40605?
Tautulli users who are running versions prior to 2.17.1 are affected by CVE-2026-40605.