CVE-2026-49995 Overview
CVE-2026-49995 is a stored Cross-Site Scripting (XSS) vulnerability [CWE-79] in Tautulli, a Python-based monitoring and tracking tool for Plex Media Server. The flaw exists in the newsletter configuration interface, where the cron field from the newsletters table is inserted into a JavaScript string context by data/interfaces/default/newsletter_config.html without safe JSON encoding. An attacker holding the Tautulli API key or administrative access can persist a crafted cron value that executes script in the Tautulli web context when any administrator opens the newsletter configuration modal. The issue is resolved in Tautulli version 2.17.2.
Critical Impact
Stored payloads persist in the database and continue executing after credential rotation until the malicious cron entry is manually removed.
Affected Products
- Tautulli versions prior to 2.17.2
- Tautulli newsletter configuration interface (data/interfaces/default/newsletter_config.html)
- Deployments exposing the Tautulli API key to untrusted callers
Discovery Timeline
- 2026-09-21 - CVE-2026-49995 published to NVD
- 2026-09-22 - Last updated in NVD database
Technical Details for CVE-2026-49995
Vulnerability Analysis
The vulnerability resides in the Mako template rendering of the newsletter configuration modal. Tautulli reads the cron value from the newsletters database table and interpolates it directly into inline JavaScript. Because the template uses the | n filter (which disables HTML escaping) without applying json.dumps, any single quote or script-terminating sequence within the stored cron string breaks out of the JavaScript string literal.
The result is stored XSS executing in the authenticated administrator's browser session within the Tautulli origin. Attackers can leverage this to invoke Tautulli's authenticated API, exfiltrate settings, pivot to the Plex environment, or modify server configuration. Because the payload is stored in the database, rotating the API key does not neutralize existing injected values.
Root Cause
The root cause is missing context-aware output encoding when transitioning user-controlled data from server state into a JavaScript string literal. Standard HTML escaping is insufficient inside <script> blocks; safe interpolation requires JSON serialization to produce a valid JavaScript literal that cannot terminate the string.
Attack Vector
Exploitation requires an actor with administrative privileges or possession of the Tautulli API key to submit a crafted cron value via the newsletter configuration endpoint. Execution is triggered passively when any administrator subsequently opens the newsletter configuration modal, satisfying the required user interaction condition.
// Patch diff from data/interfaces/default/newsletter_config.html
});
if (${newsletter['config']['custom_cron']}) {
- $('#cron_value').val('${newsletter['cron'] | n}');
+ $('#cron_value').val(${json.dumps(newsletter['cron']) | n});
} else {
try {
- cron_widget.cron('value', '${newsletter['cron']}');
+ cron_widget.cron('value', ${json.dumps(newsletter['cron']) | n});
} catch (e) {}
}
Source: GitHub Commit 12761b2. The fix wraps the cron value with json.dumps(), producing a properly quoted and escaped JavaScript literal.
Detection Methods for CVE-2026-49995
Indicators of Compromise
- Newsletter entries in the Tautulli database whose cron column contains characters such as ', <, >, \, or JavaScript keywords like alert, fetch, or eval.
- Unexpected outbound HTTP requests originating from administrator browsers immediately after opening the Tautulli newsletter configuration modal.
- Newsletter creations or modifications performed via the Tautulli API from unfamiliar source addresses or at unusual times.
Detection Strategies
- Query the Tautulli newsletters table and inspect the cron field for any value that is not a well-formed cron expression composed only of digits, *, /, ,, -, and whitespace.
- Review Tautulli HTTP access logs for POST requests to newsletter configuration endpoints that carry oversized or non-cron payloads.
- Compare rendered HTML from newsletter_config.html against expected output to identify unescaped script fragments injected into the inline JavaScript block.
Monitoring Recommendations
- Alert on API key usage from source addresses that have not previously accessed the Tautulli admin API.
- Monitor for creation of new newsletter entries followed by administrator sessions opening the configuration modal within a short window.
- Track browser-side script errors or Content Security Policy violations originating from the Tautulli origin.
How to Mitigate CVE-2026-49995
Immediate Actions Required
- Upgrade Tautulli to version 2.17.2 or later, which applies safe JSON encoding to the cron field.
- Audit the newsletters table and remove or sanitize any cron value that is not a valid cron expression before upgrading.
- Rotate the Tautulli API key and restrict its distribution to trusted automation only.
- Restrict network access to the Tautulli web interface to trusted management networks.
Patch Information
The fix is included in GitHub Release v2.17.2 and implemented by commit 12761b2. See GitHub Security Advisory GHSA-r6pg-vqxj-v75j for the maintainer's technical writeup.
Workarounds
- Avoid opening the newsletter configuration modal on unpatched instances until stored cron values have been reviewed and cleansed.
- Place Tautulli behind an authenticating reverse proxy that restricts access to the admin interface.
- Deploy a Content Security Policy that disallows inline script execution to reduce the impact of stored XSS in browser sessions.
# Verify and remove suspicious cron values in the Tautulli SQLite database
sqlite3 /path/to/tautulli.db "SELECT id, agent_name, cron FROM newsletters;"
sqlite3 /path/to/tautulli.db "UPDATE newsletters SET cron='0 0 * * *' WHERE id=<suspicious_id>;"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.