PT-2026-39836 · Pi-Hole · Pi-Hole Ftl+1

·

CVE-2026-41489

·

Published

2026-05-11

·

Updated

2026-05-11

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pi-hole Core versions 6.0 through 6.4.1 Pi-hole FTL versions 6.0 through 6.6.0
Description Two shell scripts, pihole-FTL-prestart.sh and pihole-FTL-poststop.sh, executed as root by systemd, read the files.pid path from the configuration without validation and use it in privileged file operations. An attacker with pihole privileges can write an arbitrary path into files.pid to cause the root user to delete and recreate any file on the system outside the ProtectSystem=full-restricted directories, granting write access to those files. On default installations, this allows local privilege escalation to root through the manipulation of SSH authorized keys.
Recommendations Update Core to version 6.4.2. Update FTL to version 6.6.1.

Exploit

Fix

Improper Privilege Management

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41489
GHSA-6W8X-P785-6PM4

Affected Products

Pi-Hole Core
Pi-Hole Ftl