Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to 6.4.2, a user with code execution as the unprivileged pihole user can escalate to root by replacing /etc/pihole/logrotate. The replacement is laundered to root:root ownership by pihole-FTL-prestart.sh and then parsed as root by the daily pihole flush cron, executing firstaction shell as uid 0. This issue is fixed in version 6.4.3.
References
Configurations
No configuration.
History
15 Jul 2026, 13:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/pi-hole/pi-hole/security/advisories/GHSA-h8w9-qx2v-wrww - |
14 Jul 2026, 22:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-14 22:17
Updated : 2026-07-16 05:16
NVD link : CVE-2026-50130
Mitre link : CVE-2026-50130
CVE.ORG link : CVE-2026-50130
JSON object : View
Products Affected
No product.
CWE
CWE-282
Improper Ownership Management
