API Authorization Bypass in Pi-hole's FTL by Pi-hole
CVE-2026-35491
6.1MEDIUM
What is CVE-2026-35491?
Pi-hole's FTL service, which powers the web interface and statistics for Pi-hole, has a significant vulnerability that allows unauthorized CLI sessions to bypass essential security checks. Specifically, the Teleporter API endpoint was incorrectly configured, allowing CLI-scoped sessions to perform unauthorized configuration changes by importing Teleporter archives. This flaw compromises the integrity of network configurations and carries the risk of unauthorized alterations, making it vital for users to update to version 6.6 or later for mitigation.
Affected Version(s)
FTL >= 6.0, < 6.6
