Junglewise Threat Intelligence

CVE-2026-43986: Tautulli unauthenticated SSRF in image route

CVE-2026-43986 · Severity: critical · CVSS 9.9 · Published 2026-06-04

Technologies: Tautulli. Vendors: Tautulli.

Executive brief

Tautulli, a monitoring tool for Plex Media Servers, contains a vulnerability that allows attackers to perform unauthorized network requests from the server. By exploiting a flaw in how images are cached and retrieved, a low-privileged guest user can force the server to connect to arbitrary internal or external web addresses. This can lead to the exposure of sensitive internal data or be used to launch further attacks against the local network, even by users who are not logged in once the initial setup is performed.

Technical details

Tautulli exposes a public `/image/<hash>` route that resolves entries from the `image_hash_lookup` table and replays them through server-side image fetch logic. A low-privilege guest user can seed a malicious URL into this table via the authenticated `/pms_image_proxy` endpoint. Because the hash generation is deterministic and uses values disclosed during sign-in (such as the PMS UUID), an attacker can calculate the hash offline. Once seeded, any unauthenticated user can request the specific `/image/<hash>` URL, causing the Tautulli host to fetch the attacker-chosen URL using the administrator's PMS token. This vulnerability effectively upgrades an authenticated SSRF primitive into a persistent, unauthenticated SSRF gadget. The issue is patched in version 2.17.1.

Affected products

  • Tautulli Tautulli < 2.17.1

Timeline

  • 2026-05-04: patched: Version 2.17.1 released
  • 2026-05-27: advisory: GitHub Security Advisory published
  • 2026-06-04: disclosed: CVE published to NVD

References

Related threats