CrowdSecLive Exploit Tracker
Limited ExploitationCVE-2026-31831Public Exploit

Tautulli - Path Traversal (CVE-2026-31831)

PublishedMar 30, 2026
First SeenAug 19, 2026
Last Seen
Reported
CVSS8.7
pythonweb_application

Description

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /newsletter/image/images API endpoint is vulnerable to path traversal, allowing unauthenticated attackers to read arbitrary files from the application server's filesystem. This issue has been patched in version 2.17.0.

psychologyCrowdSec Analysis

CVE-2026-31831 is a high-severity path traversal vulnerability in Tautulli versions before 2.17.0. The flaw in the /newsletter/image/images API endpoint allows unauthenticated remote attackers to read arbitrary files from the application server’s filesystem, potentially exposing sensitive configuration data, credentials, and other confidential information.

CrowdSec has been tracking this vulnerability and its exploits since 3rd of August 2026.

According to CrowdSec data, while opportunistic exploitation dominates, a portion of threat actors trying to exploit CVE-2026-31831 apply basic targeting methods such as port or service detection. This indicates emerging patterns of selective targeting. In addition, according to the CrowdSec network, attack volume against CVE-2026-31831 has dipped slightly compared to the previous week. Although still commonly targeted, the decline suggests a cooling-off period. Long-term relevance remains, but attention is waning.

Attackers target the unauthenticated /newsletter/image/images endpoint with URL-encoded parent-directory traversal sequences to escape the intended image directory and read local files. Detection should identify traversal patterns such as ..%2F in this path, particularly when the response contains Tautulli configuration markers like [General], [PMS], or pms_identifier.

lock

Full Intelligence Available

Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.

EventDate
CVE Published2026-03-30
Rule Released2026-08-03
CrowdSec First Seen2026-08-19

Remediation & Protection

lock to download blocklists, subscribe to firewalls, and access IP intelligence.