Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35521

29
FAUCET Score

OVERVIEW: CVE-2026-35521 is a Remote Code Execution vulnerability affecting Pi-hole FTL versions 6.0 through 6.5. The vulnerability exists in the DHCP hosts configuration parameter where an authenticated attacker can inject arbitrary dnsmasq configuration directives using newline characters, leading to command execution on affected systems. The issue has been patched in version 6.6. SEVERITY: The vulnerability carries a CVSS score of 8.8 (HIGH) with a network-based attack vector requiring only low complexity and valid credentials. No user interaction is required, and successful exploitation results in complete compromise of system confidentiality, integrity, and availability. The FAUCET Risk Score of 42/100 indicates moderate overall risk when considering additional contextual factors. EXPLOITATION STATUS: There is no evidence of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities list, and community attention is currently minimal as indicated by the low EPSS score of 0.002. Organizations should prioritize patching to version 6.6 to eliminate this attack vector, particularly in environments where administrative access to the Pi-hole interface is not properly restricted.

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.0, <= 6.5CPE matchmatch criteria
cpe:2.3:a:pi-hole:ftldns:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.69%
Probability of exploitation in next 30 days
EPSS Percentile
48.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0069 is in the 41st percentile among its peer group of 17,844 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / pi-hole/FTL/security/advisories/GHSA-vfmq-jrx3-wv3c
ExploitVendor Advisory