Arbitrary Command Execution Vulnerability in Pi-hole FTL
CVE-2026-39849

8.7HIGH

Key Information:

Vendor

Pi-hole

Status
Vendor
CVE Published:
5 May 2026

What is CVE-2026-39849?

A vulnerability in Pi-hole FTL enables attackers to exploit the dns.interface configuration field by injecting arbitrary directives into the dnsmasq configuration file. This can occur on installations lacking an admin password, allowing network-adjacent attackers to enable the DHCP server and execute commands on the host. The issue arises as newline characters are improperly validated, enabling payloads within the size constraints to be executed. This flaw has been addressed in version 6.6.1.

Affected Version(s)

FTL < 6.6.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.