OVERVIEW: CVE-2026-35521 is a Remote Code Execution vulnerability affecting Pi-hole FTL versions 6.0 through 6.5. The vulnerability exists in the DHCP hosts configuration parameter where an authenticated attacker can inject arbitrary dnsmasq configuration directives using newline characters, leading to command execution on affected systems. The issue has been patched in version 6.6. SEVERITY: The vulnerability carries a CVSS score of 8.8 (HIGH) with a network-based attack vector requiring only low complexity and valid credentials. No user interaction is required, and successful exploitation results in complete compromise of system confidentiality, integrity, and availability. The FAUCET Risk Score of 42/100 indicates moderate overall risk when considering additional contextual factors. EXPLOITATION STATUS: There is no evidence of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities list, and community attention is currently minimal as indicated by the low EPSS score of 0.002. Organizations should prioritize patching to version 6.6 to eliminate this attack vector, particularly in environments where administrative access to the Pi-hole interface is not properly restricted.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0, <= 6.5CPE matchmatch criteria | cpe:2.3:a:pi-hole:ftldns:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.