Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35491

21
FAUCET Score

OVERVIEW: CVE-2026-35491 is an authorization bypass vulnerability in Pi-hole FTL versions 6.0 through 6.5 that affects the /api/teleporter endpoint. The vulnerability allows users with CLI-scoped API sessions, which are intended to be read-only, to circumvent access controls and modify system configuration by importing Teleporter archives. While the /api/config endpoint correctly restricts CLI sessions from making configuration changes, the /api/teleporter endpoint fails to enforce the same restrictions, creating an unintended privilege escalation path. SEVERITY: The vulnerability requires local access and low privileges to exploit, with a CVSS 3.1 score of 6.1 (MEDIUM). The attack has low complexity and no user interaction requirement. While confidentiality is not impacted, the vulnerability enables high-integrity impacts through unauthorized configuration modification and causes some availability degradation. The EPSS score of 0.00014 indicates this vulnerability has a lower probability of exploitation compared to other known vulnerabilities. EXPLOITATION STATUS: There is no evidence of active exploitation in the wild, as the vulnerability does not appear on the KEV catalog or Hot List. Community attention appears minimal based on the low EPSS score. The vulnerability has been patched in Pi-hole FTL version 6.6, and organizations should prioritize upgrading to mitigate this authorization bypass risk.

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.0, < 6.6CPE matchmatch criteria
cpe:2.3:a:pi-hole:ftldns:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.1MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
1.8
Impact Score
4.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
5.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0016 is in the 32nd percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / pi-hole/FTL/security/advisories/GHSA-r7g8-3fj7-m5qq
ExploitMitigationVendor Advisory