CVE-2026-50130
Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to 6.4.2, a user with code execution as the unprivileged pihole user can escalate to root by replacing /etc/pihole/logrotate. The replacement is laundered to root:root ownership by pihole-FTL-prestart.sh and then parsed as root by the daily pihole flush cron, executing firstaction shell as uid 0. This issue is fixed in version 6.4.3.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.25%
- CWE
- CWE-282
- Published
- 2026-07-14
- Last modified
- 2026-07-16
Affected products
- pi-hole pi-hole
Weakness type
Related vulnerabilities
- CVE-2026-86769 — Snipe-IT before 8.7.0 Audit Log Misattribution via Consumables Checkout
- CVE-2026-40214 — In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project...
- CVE-2026-3867 — An improper ownership management vulnerability has been identified in Moxa’s Secure Router. Because...
- CVE-2026-23514 — Kiteworks Core before 9.2.2 is vulnerable to Improper Ownership Management
- CVE-2025-57732 — In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory...
- CVE-2025-1112 — IBM OpenPages with Watson information disclosure
- CVE-2025-46416 — The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can...
- CVE-2025-3629 — IBM InfoSphere Information Server file manipulation