CVE-2026-43985 - Taultulli has CSRF in /configUpdate via missing anti-CSRF and method restriction that allows admin credential takeover
CVE ID :CVE-2026-43985 Published : June 4, 2026, 4:16 p.m. | 57 minutes ago Description :Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `configUpdate` as a state-changing administrator endpoint, but the route does not enforce...