# CVE-2026-31831: Tautulli - Path Traversal

> Live exploitation tracking for CVE-2026-31831 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2026-31831

## Key facts

- **Exploitation phase:** Limited Exploitation. The vulnerability is known but shows very limited attacker interest or exploitation activity.
- **CVSS score:** 8.7
- **Public exploit available:** Yes
- **Affected products:** Tautulli
- **Weaknesses:** CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
- **Tags:** python, web_application

## Description

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /newsletter/image/images API endpoint is vulnerable to path traversal, allowing unauthenticated attackers to read arbitrary files from the application server's filesystem. This issue has been patched in version 2.17.0.

## CrowdSec analysis

[CVE-2026-31831](https://euvd.enisa.europa.eu/vulnerability/CVE-2026-31831) is a high-severity path traversal vulnerability in Tautulli versions before 2.17.0. The flaw in the `/newsletter/image/images` API endpoint allows unauthenticated remote attackers to read arbitrary files from the application server’s filesystem, potentially exposing sensitive configuration data, credentials, and other confidential information.

CrowdSec has been tracking this vulnerability and its exploits since 3rd of August 2026.

According to CrowdSec data, while opportunistic exploitation dominates, a portion of threat actors trying to exploit CVE-2026-31831 apply basic targeting methods such as port or service detection. This indicates emerging patterns of selective targeting.
In addition, according to the CrowdSec network, attack volume against CVE-2026-31831 has dipped slightly compared to the previous week. Although still commonly targeted, the decline suggests a cooling-off period. Long-term relevance remains, but attention is waning.

Attackers target the unauthenticated `/newsletter/image/images` endpoint with URL-encoded parent-directory traversal sequences to escape the intended image directory and read local files. Detection should identify traversal patterns such as `..%2F` in this path, particularly when the response contains Tautulli configuration markers like `[General]`, `[PMS]`, or `pms_identifier`.

## Timeline

- 2026-03-30: CVE Published. CVE-2026-31831 is published to NVD.
- 2026-08-03: Rule Released. CrowdSec releases a rule to detect CVE-2026-31831 exploitation attempts against the CrowdSec Network.
- 2026-08-19: CrowdSec First Seen. CrowdSec observes in-the-wild exploitation of CVE-2026-31831 for the first time.

## References

- https://github.com/Tautulli/Tautulli/security/advisories/GHSA-xp55-2pf4-fv8m
- https://github.com/Tautulli/Tautulli/releases/tag/v2.17.0
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-31831.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2026-31831) follows observed exploitation activity for CVE-2026-31831. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
