Arbitrary Command Execution Vulnerability in Pi-hole FTL
CVE-2026-39849
8.7HIGH
What is CVE-2026-39849?
A vulnerability in Pi-hole FTL enables attackers to exploit the dns.interface configuration field by injecting arbitrary directives into the dnsmasq configuration file. This can occur on installations lacking an admin password, allowing network-adjacent attackers to enable the DHCP server and execute commands on the host. The issue arises as newline characters are improperly validated, enabling payloads within the size constraints to be executed. This flaw has been addressed in version 6.6.1.
Affected Version(s)
FTL < 6.6.1
