Vulnerability Details CVE-2026-31799
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 2.14.2 to before version 2.17.0 for parameters "before" and "after" and from version 2.1.0-beta to before version 2.17.0 for parameters "section_id" and "user_id", the /api/v2?cmd=get_home_stats endpoint passes the section_id, user_id, before, and after query parameters directly into SQL via Python %-string formatting without parameterization. An attacker who holds the Tautulli admin API key can inject arbitrary SQL and exfiltrate any value from the Tautulli SQLite database via boolean-blind inference. This issue has been patched in version 2.17.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 3.5%
CVSS Severity
CVSS v3 Score 4.9
Products affected by CVE-2026-31799
-
cpe:2.3:a:tautulli:tautulli:2.1.0
-
cpe:2.3:a:tautulli:tautulli:2.1.1
-
cpe:2.3:a:tautulli:tautulli:2.1.10
-
cpe:2.3:a:tautulli:tautulli:2.1.11
-
cpe:2.3:a:tautulli:tautulli:2.1.12
-
cpe:2.3:a:tautulli:tautulli:2.1.13
-
cpe:2.3:a:tautulli:tautulli:2.1.14
-
cpe:2.3:a:tautulli:tautulli:2.1.15
-
cpe:2.3:a:tautulli:tautulli:2.1.16
-
cpe:2.3:a:tautulli:tautulli:2.1.17
-
cpe:2.3:a:tautulli:tautulli:2.1.18
-
cpe:2.3:a:tautulli:tautulli:2.1.19
-
cpe:2.3:a:tautulli:tautulli:2.1.2
-
cpe:2.3:a:tautulli:tautulli:2.1.20
-
cpe:2.3:a:tautulli:tautulli:2.1.21
-
cpe:2.3:a:tautulli:tautulli:2.1.22
-
cpe:2.3:a:tautulli:tautulli:2.1.23
-
cpe:2.3:a:tautulli:tautulli:2.1.24
-
cpe:2.3:a:tautulli:tautulli:2.1.25
-
cpe:2.3:a:tautulli:tautulli:2.1.26
-
cpe:2.3:a:tautulli:tautulli:2.1.3
-
cpe:2.3:a:tautulli:tautulli:2.1.4
-
cpe:2.3:a:tautulli:tautulli:2.1.5
-
cpe:2.3:a:tautulli:tautulli:2.1.6
-
cpe:2.3:a:tautulli:tautulli:2.1.7
-
cpe:2.3:a:tautulli:tautulli:2.1.8
-
cpe:2.3:a:tautulli:tautulli:2.1.9