Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35519

29
FAUCET Score

OVERVIEW CVE-2026-35519 is a Remote Code Execution vulnerability affecting Pi-hole FTL versions 6.0 through 6.5. The flaw exists in the DNS host record configuration parameter (dns.hostRecord) within FTLDNS, which provides the API and statistics engine for Pi-hole's web interface. An authenticated attacker can exploit this vulnerability by injecting newline characters to insert arbitrary dnsmasq configuration directives, resulting in command execution on the affected system. The vulnerability has been patched in version 6.6. SEVERITY This vulnerability carries a CVSS v3.1 score of 8.8 (HIGH) with a network-based attack vector requiring low complexity and low privileges. The attack requires valid authentication credentials but no user interaction. Impact is severe across all three security dimensions: attackers can achieve high-level confidentiality, integrity, and availability compromise on the underlying system. The FAUCET Risk Score of 42.0/100 indicates moderate concern, though the extremely low EPSS score (0.0023) suggests minimal real-world exploitation probability currently. EXPLOITATION STATUS There is no indication of active exploitation in the wild, as CVE-2026-35519 is not listed on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat intelligence hot lists. No public exploit code appears to be widely available, and community attention has been limited. Organizations running Pi-hole FTL versions 6.0-6.5 should prioritize patching to version 6.6 to mitigate this risk, particularly in environments where authentication access cannot be strictly controlled.

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.0, <= 6.5CPE matchmatch criteria
cpe:2.3:a:pi-hole:ftldns:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.54%
Probability of exploitation in next 30 days
EPSS Percentile
42.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0054 is in the 31st percentile among its peer group of 17,844 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryvendor investigatingvia nvd_reference
View patch

References

github.com / pi-hole/FTL/security/advisories/GHSA-wxhv-w77q-6qwp
Vendor Advisory