OVERVIEW: CVE-2026-35491 is an authorization bypass vulnerability in Pi-hole FTL versions 6.0 through 6.5 that affects the /api/teleporter endpoint. The vulnerability allows users with CLI-scoped API sessions, which are intended to be read-only, to circumvent access controls and modify system configuration by importing Teleporter archives. While the /api/config endpoint correctly restricts CLI sessions from making configuration changes, the /api/teleporter endpoint fails to enforce the same restrictions, creating an unintended privilege escalation path. SEVERITY: The vulnerability requires local access and low privileges to exploit, with a CVSS 3.1 score of 6.1 (MEDIUM). The attack has low complexity and no user interaction requirement. While confidentiality is not impacted, the vulnerability enables high-integrity impacts through unauthorized configuration modification and causes some availability degradation. The EPSS score of 0.00014 indicates this vulnerability has a lower probability of exploitation compared to other known vulnerabilities. EXPLOITATION STATUS: There is no evidence of active exploitation in the wild, as the vulnerability does not appear on the KEV catalog or Hot List. Community attention appears minimal based on the low EPSS score. The vulnerability has been patched in Pi-hole FTL version 6.6, and organizations should prioritize upgrading to mitigate this authorization bypass risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0, < 6.6CPE matchmatch criteria | cpe:2.3:a:pi-hole:ftldns:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.