API Authorization Bypass in Pi-hole's FTL by Pi-hole
CVE-2026-35491

6.1MEDIUM

Key Information:

Vendor

Pi-hole

Status
Vendor
CVE Published:
7 April 2026

What is CVE-2026-35491?

Pi-hole's FTL service, which powers the web interface and statistics for Pi-hole, has a significant vulnerability that allows unauthorized CLI sessions to bypass essential security checks. Specifically, the Teleporter API endpoint was incorrectly configured, allowing CLI-scoped sessions to perform unauthorized configuration changes by importing Teleporter archives. This flaw compromises the integrity of network configurations and carries the risk of unauthorized alterations, making it vital for users to update to version 6.6 or later for mitigation.

Affected Version(s)

FTL >= 6.0, < 6.6

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.