Pi-hole FTL: Unauthenticated Session Hijacking via Race Condition on Global Session Buffer
CVE-2026-44693

8.8HIGH

Key Information:

Vendor

Pi-hole

Status
Vendor
CVE Published:
10 June 2026

What is CVE-2026-44693?

Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. Prior to version 6.6.1, Pi-hole FTL contains a race condition vulnerability in the HTTP session management subsystem, introduced with the v6.0 rewrite of the embedded CivetWeb-based web server. This issue has been patched in version 6.6.1.

Affected Version(s)

FTL < 6.6.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.