Junglewise Threat Intelligence

CVE-2026-52835: Tautulli path traversal in file upload handlers

CVE-2026-52835 · Severity: info · Published 2026-09-21

Technologies: Tautulli. Vendors: Tautulli.

Executive brief

Tautulli is a monitoring and tracking tool for Plex Media Server that allows administrators to manage configurations and databases. Prior to version 2.17.2, an authenticated administrator with the API key could upload files with specially crafted names containing path traversal sequences (../) to write files outside the intended cache directory, potentially allowing them to tamper with configuration, disrupt the service, or achieve code execution.

Technical details

The vulnerability exists in the import_config and import_database handlers in plexpy/webserve.py, which join attacker-controlled multipart upload filenames directly to CACHE_DIR without canonicalization (basename reduction) or containment checks. An authenticated caller can submit filenames with ../ segments to write outside the intended directory. The write scope is limited to paths the Tautulli process has permission to access, but the lack of filename sanitization before joining enables arbitrary file creation or overwrite within process permissions. Fixed in 2.17.2 by applying os.path.basename to reduce filenames before joining.

Affected products

  • Tautulli Tautulli before 2.17.2

Timeline

  • 2026-06-16: disclosed: Fixed in version 2.17.2
  • 2026-09-21: advisory

References

Related threats