← العودة للجدول
CVE-2026-43986
CVE-2026-43986 — Tautulli is a Python based monitoring and tracking tool for Plex Media Server. V
📅 2026-06-04
🔴 Critical 🔥 No NVD Exploit Web CVSS 9.9 🎯 EPSS 0.04%

📋 الوصف الكامل

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose a public `/image/` route that resolves attacker-controlled entries from `image_hash_lookup` and replays them through the same server-side image fetch logic used by authenticated image proxying. A low-privilege guest user can seed a malicious external image URL into this lookup table and t

💻 الأنظمة المتأثرة

Tautulli is a

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-43986

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v2.17.1

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←