CVE-2026-50130

Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to 6.4.2, a user with code execution as the unprivileged pihole user can escalate to root by replacing /etc/pihole/logrotate. The replacement is laundered to root:root ownership by pihole-FTL-prestart.sh and then parsed as root by the daily pihole flush cron, executing firstaction shell as uid 0. This issue is fixed in version 6.4.3.
Configurations

No configuration.

History

15 Jul 2026, 13:17

Type Values Removed Values Added
References () https://github.com/pi-hole/pi-hole/security/advisories/GHSA-h8w9-qx2v-wrww - () https://github.com/pi-hole/pi-hole/security/advisories/GHSA-h8w9-qx2v-wrww -

14 Jul 2026, 22:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-14 22:17

Updated : 2026-07-16 05:16


NVD link : CVE-2026-50130

Mitre link : CVE-2026-50130

CVE.ORG link : CVE-2026-50130


JSON object : View

Products Affected

No product.

CWE
CWE-282

Improper Ownership Management