PT-2026-39836 · Pi-Hole · Pi-Hole Ftl+1
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Pi-hole Core versions 6.0 through 6.4.1
Pi-hole FTL versions 6.0 through 6.6.0
Description
Two shell scripts,
pihole-FTL-prestart.sh and pihole-FTL-poststop.sh, executed as root by systemd, read the files.pid path from the configuration without validation and use it in privileged file operations. An attacker with pihole privileges can write an arbitrary path into files.pid to cause the root user to delete and recreate any file on the system outside the ProtectSystem=full-restricted directories, granting write access to those files. On default installations, this allows local privilege escalation to root through the manipulation of SSH authorized keys.Recommendations
Update Core to version 6.4.2.
Update FTL to version 6.6.1.
Exploit
Fix
Improper Privilege Management
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pi-Hole Core
Pi-Hole Ftl