PT-2026-58857 · Pi-Hole · Pi-Hole
CVE-2026-50130
·
Published
2026-07-14
·
Updated
2026-07-14
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Pi-hole versions 6.0 through 6.4.2
Description
A user with code execution capabilities as the unprivileged
pihole user can escalate privileges to root. This occurs by replacing the /etc/pihole/logrotate file, which is then changed to root:root ownership by the pihole-FTL-prestart.sh script. Subsequently, the daily pihole flush cron job parses this file as root, executing the firstaction shell command as uid 0.Recommendations
Update Pi-hole to version 6.4.3.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pi-Hole