All verified exploits

CVE-2026-28505 Remote Code Execution via Notification Template Sandbox Bypass

Deterministic high Tautulli Added cve-verified-cve-2026-28505

Detects Tautulli instances before version 2.17.0 where the notification template eval sandbox can be bypassed via nested code objects (lambda expressions). The str_eval() function only checks allowlisted names at the top-level code object — attributes accessed inside lambdas are stored in co_consts and never validated. When NOTIFY_TEXT_EVAL is enabled in Advanced Settings, an admin can execute arbitrary Python commands on the server. Update to Tautulli v2.17.0 or later.

Is your app exploitable through CVE-2026-28505?

Scan your domain free