CVE-2026-49995: Tautulli: Stored Cross-Site Scripting (XSS) in the newsletter

Published Sep 21, 2026
·
Updated

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the newsletter cron field stored in the newsletters table is inserted by data/interfaces/default/newsletterconfig.html into a JavaScript string without safe JSON encoding. An administrator or caller with the Tautulli API key can store a crafted cron value, and an administrator who later opens the newsletter configuration modal passively triggers script execution in the Tautulli web context. The stored value persists in the database and can continue to execute after credential rotation until it is removed. This issue is fixed in version 2.17.2.

Affected Software

1 affected component
Tautulli Tautulli<2.17.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Tautulli to a version that resolves this vulnerability.

    Fixed in 2.17.2
  2. Operational

    Remove any crafted persisted newsletter cron payload stored in the Tautulli newsletters table; note the malicious value can continue to execute after credential rotation until it is removed.

Event History

Sep 21, 2026
CVE Published
via MITRE·07:13 PM
Data Sourced
via MITRE·07:13 PM
DescriptionWeakness

Frequently Asked Questions

1

Who can inject the malicious value, and who triggers it?

An administrator or a caller with the Tautulli API key can store a crafted newsletter cron value. Script execution occurs when an administrator later opens the newsletter configuration modal.

2

Which deployments are affected?

Tautulli versions prior to 2.17.2 are affected. The issue involves the newsletter cron field stored in the newsletters table.

3

What should be done if upgrading cannot happen immediately?

Remove any untrusted or suspicious values from the newsletter cron field in the newsletters table. Rotating credentials alone does not remove the stored payload, which can continue executing until it is removed.

4

How can I determine whether a stored payload may still be present?

Inspect newsletter cron values in the newsletters table for crafted or unexpected content. A payload may execute when an administrator opens the newsletter configuration modal, even if credentials have since been rotated.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203