CVE-2026-43985
Last modified
CVE-2026-43985 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `configUpdate` as a state-changing administrator endpoint, but the route does not enforce `POST` and does not use any anti-CSRF token. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `configUpdate` as a state-changing administrator endpoint, but the route does not enforce `POST` and does not use any anti-CSRF token. In the default form and JWT-based authentication mode, the administrator session cookie is issued with `SameSite=Lax`, which still permits top-level cross-site navigation requests. An attacker can exploit this by luring a logged-in administrator to a malicious page that submits a cross-site request to `/configUpdate` and overwrites the local administrator username and password. The attacker can then sign in directly with the chosen credentials and take over the Tautulli administrative interface. Version 2.17.1 patches the issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-43985?
How severe is CVE-2026-43985?
How do I fix CVE-2026-43985?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-43979Local Deep Research is an AI-powered research assistant for …5
- CVE-2026-4398Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-43981Algernon is a small self-contained pure-Go web server. Prior…8.2
- CVE-2026-43982Algernon is a small self-contained pure-Go web server. Prior…8.7
- CVE-2026-43983Pocket ID is an OIDC provider that allows users to authentic…8.1
- CVE-2026-43984Tautulli is a Python based monitoring and tracking tool for …8.9
- CVE-2026-43986Tautulli is a Python based monitoring and tracking tool for …9.9
- CVE-2026-43988Vanetza is an open-source implementation of the ETSI C-ITS p…7.5
- CVE-2026-43989JunoClaw is an agentic AI platform built on Juno Network. Pr…8.5
- CVE-2026-4399Prompt injection vulnerability in 1millionbot Millie chatbot…7.5
- CVE-2026-43990JunoClaw is an agentic AI platform built on Juno Network. Pr…8.4
- CVE-2026-43991JunoClaw is an agentic AI platform built on Juno Network. Pr…8.4
Are you affected by CVE-2026-43985?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
