Junglewise Threat Intelligence

CVE-2026-41065: Tautulli remote code execution in newsletter custom template directory

CVE-2026-41065 · Severity: info · CVSS 8.9 · Published 2026-06-04

Technologies: Tautulli. Vendors: Tautulli.

Executive brief

Tautulli, a monitoring tool for Plex Media Servers, contains a vulnerability that allows attackers to take complete control of the server. On new installations that haven't been fully set up, an attacker can remotely execute malicious commands without any password. On existing installations, a user with administrative privileges can also exploit this flaw to run unauthorized code on the underlying system.

Technical details

Tautulli versions prior to 2.17.1 are vulnerable to Remote Code Execution (RCE) due to two compounding issues. First, fresh installations default to an empty password, which disables the authentication middleware for all management endpoints. Second, the 'newsletter_custom_dir' configuration parameter is passed unsanitized to the Mako TemplateLookup engine. An attacker can point this directory to a remote SMB or NFS share containing a malicious Mako template (using <% %> blocks for Python execution) and trigger its rendering via the 'real_newsletter' endpoint. This allows for unauthenticated RCE on new installs and authenticated RCE for administrators on configured installs. The fix in version 2.17.1 introduces anti-CSRF tokens, enforces POST methods, and requires manual configuration to allow mounted folders for templates.

Affected products

  • Tautulli Tautulli <= 2.17.0

Timeline

  • 2026-05-04: patched: Version 2.17.1 released
  • 2026-05-27: advisory: GitHub Security Advisory published
  • 2026-06-04: disclosed: CVE-2026-41065 published to NVD

References

Related threats