CVE-2026-32275 is a critical cross-origin script injection vulnerability (CWE-79) affecting Tautulli, a Python-based monitoring tool for Plex Media Server, in versions 1.3.10 through 2.16.x due to an unsanitized JSONP callback parameter. Rated 9.1 Critical (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N), this flaw allows unauthenticated attackers to perform API key theft and arbitrary script injection with high confidentiality and integrity impact. Despite its severity, there is currently no evidence of active exploitation, public exploit code availability (Metasploit, Nuclei, ExploitDB), or significant community discussion, as indicated by its very low EPSS score.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.3.10, < 2.17.0CPE matchmatch criteria | cpe:2.3:a:tautulli:tautulli:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.