Junglewise Threat Intelligence

CVE-2026-43985: Tautulli CSRF in configUpdate allows administrator takeover

CVE-2026-43985 · Severity: high · CVSS 8.8 · Published 2026-06-04

Technologies: Tautulli. Vendors: Tautulli.

Executive brief

Tautulli is a monitoring and management tool for Plex Media Server. A security flaw allows an attacker to trick a logged-in administrator into visiting a malicious website that silently changes the administrator's username and password. This results in a complete takeover of the Tautulli management interface, allowing the attacker to access sensitive logs, configuration data, and server settings.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the `/configUpdate` endpoint of Tautulli. The endpoint, which handles sensitive configuration changes including administrator credentials, fails to enforce the POST method and lacks anti-CSRF tokens. Furthermore, the application issues JWT session cookies with `SameSite=Lax`, which permits top-level cross-site GET requests to carry the session cookie. An attacker can lure an authenticated administrator to a malicious site that triggers a request to `/configUpdate` with new `http_username` and `http_password` parameters. This overwrites the local administrator credentials in the configuration file, allowing the attacker to subsequently log in with full administrative privileges. The issue is fixed in version 2.17.1 by enforcing POST methods and implementing anti-CSRF tokens.

Affected products

  • Tautulli Tautulli < 2.17.1

Timeline

  • 2026-05-04: patched: Version 2.17.1 released
  • 2026-05-27: advisory: GitHub Security Advisory published
  • 2026-06-04: disclosed: CVE published to NVD

References

Related threats