Skip to main content
Vulnerability Database/CVE-2026-52835

CVE-2026-52835: Tautulli Path Traversal Vulnerability

CVE-2026-52835 is a path traversal flaw in Tautulli that allows authenticated attackers to write files outside intended directories, potentially enabling code execution. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-52835 Overview

CVE-2026-52835 is a path traversal vulnerability [CWE-22] in Tautulli, a Python-based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.2 fail to sanitize attacker-controlled filenames in the import_config handler and the database_file branch of import_database within plexpy/webserve.py. The handlers join the multipart filename field directly to CACHE_DIR without applying os.path.basename or a containment check. An authenticated caller with the instance API key can supply parent-directory segments in the filename to write files outside CACHE_DIR.

Critical Impact

Authenticated attackers can write or overwrite files outside the intended cache directory, enabling configuration tampering, service disruption, or code execution within the Tautulli process context.

Affected Products

  • Tautulli versions prior to 2.17.2
  • plexpy/webserve.pyimport_config handler
  • plexpy/webserve.pyimport_database handler (database_file branch)

Discovery Timeline

  • 2026-09-21 - CVE-2026-52835 published to NVD
  • 2026-09-21 - Last updated in NVD database

Technical Details for CVE-2026-52835

Vulnerability Analysis

The vulnerability resides in two upload handlers in plexpy/webserve.py. Both handlers accept a multipart file object and construct a destination path using os.path.join(plexpy.CONFIG.CACHE_DIR, <filename>). The filename attribute originates from the HTTP multipart request and remains attacker-controlled. Python's os.path.join treats absolute paths or parent-directory traversal sequences as authoritative components, so a filename containing ../ segments escapes CACHE_DIR.

The write occurs before file-content validation runs. An attacker with a valid API key can create or overwrite arbitrary files anywhere the Tautulli process holds write permissions. This positions the flaw as an authenticated arbitrary file write rather than an unauthenticated remote exploit.

Root Cause

The handlers omit os.path.basename normalization and lack a containment check that verifies the resolved destination remains within CACHE_DIR. Trusting the client-supplied filename violates standard secure file upload guidance.

Attack Vector

Exploitation requires network access to the Tautulli web interface and possession of the instance API key. The attacker submits a multipart POST to the import endpoint with a filename field containing traversal segments such as ../../etc/target.conf. The upload is written to the traversed path before any content validation runs.

python
# Patch from plexpy/webserve.py (v2.17.2)
# Source: https://github.com/Tautulli/Tautulli/commit/8c7c1a5ab09a6cca00aec995df07ce24680e7f31

            database_path = shutil.copyfile(database_path, database_cache_path)

        elif database_file:
-            database_path = os.path.join(plexpy.CONFIG.CACHE_DIR, database_file.filename + '.import.db')
+            database_file_name = os.path.basename(database_file.filename)
+            database_path = os.path.join(plexpy.CONFIG.CACHE_DIR, database_file_name + '.import.db')
            logger.info("Received database file '%s' for import. Saving to cache: %s",
-                        database_file.filename, database_path)
+                        database_file_name, database_path)
            with open(database_path, 'wb') as f:
                 while True:
                     data = database_file.file.read(8192)

The fix applies os.path.basename to the client-supplied filename, stripping any directory components before joining the path.

Detection Methods for CVE-2026-52835

Indicators of Compromise

  • Multipart HTTP requests to Tautulli import endpoints containing ../ or ..\ sequences in the filename parameter.
  • Unexpected file creation or modification outside the configured CACHE_DIR under the Tautulli service account.
  • Modification of Tautulli configuration files, Python modules, or startup scripts without a corresponding administrative action.
  • Access log entries showing calls to import_config or import_database from unfamiliar source addresses.

Detection Strategies

  • Inspect Tautulli access logs for POST requests to import handlers correlated with abnormal filenames.
  • Monitor filesystem events on hosts running Tautulli for writes originating from the Tautulli process outside CACHE_DIR.
  • Alert on any use of the instance API key from source addresses that fall outside expected administrative ranges.

Monitoring Recommendations

  • Enable verbose logging in Tautulli and forward logs to a central SIEM for retention and correlation.
  • Deploy file integrity monitoring on directories writable by the Tautulli process, including configuration and Python module paths.
  • Track API key usage patterns and rotate keys after any suspicious activity.

How to Mitigate CVE-2026-52835

Immediate Actions Required

  • Upgrade Tautulli to version 2.17.2 or later, which applies os.path.basename sanitization to uploaded filenames.
  • Rotate the Tautulli instance API key if you suspect exposure or if the service has been reachable from untrusted networks.
  • Restrict access to the Tautulli web interface using network controls or an authenticating reverse proxy.

Patch Information

The vendor released the fix in Tautulli v2.17.2. The source commit applies os.path.basename to both the import_config and import_database handlers. Additional details are available in the GitHub Security Advisory GHSA-8ww5-pp25-3jm8.

Workarounds

  • Block external access to the Tautulli web interface until the upgrade is applied.
  • Run the Tautulli process under a dedicated low-privilege account with write access limited to CACHE_DIR and required data directories.
  • Place Tautulli behind a reverse proxy that inspects multipart uploads and rejects filenames containing ../ or absolute path prefixes.
bash
# Verify installed Tautulli version and upgrade
git -C /opt/Tautulli describe --tags
git -C /opt/Tautulli fetch --tags
git -C /opt/Tautulli checkout v2.17.2
systemctl restart tautulli

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.