CVE-2026-43986 - Critical SSRF in Tautulli < 2.17.1. Low-privilege users can force server-side fetches via unauthenticated endpoint. CVSS 9.9. No patch yet. Isolate or disable immediately. #CVE #Tautulli #infosec

https://www.valtersit.com/cve/CVE-2026-43986/

CVE-2026-43986 | Tautulli | Valters IT Hub

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose a public `/image/` route that resolves attac...

Valters IT Hub