OVERVIEW CVE-2026-35519 is a Remote Code Execution vulnerability affecting Pi-hole FTL versions 6.0 through 6.5. The flaw exists in the DNS host record configuration parameter (dns.hostRecord) within FTLDNS, which provides the API and statistics engine for Pi-hole's web interface. An authenticated attacker can exploit this vulnerability by injecting newline characters to insert arbitrary dnsmasq configuration directives, resulting in command execution on the affected system. The vulnerability has been patched in version 6.6. SEVERITY This vulnerability carries a CVSS v3.1 score of 8.8 (HIGH) with a network-based attack vector requiring low complexity and low privileges. The attack requires valid authentication credentials but no user interaction. Impact is severe across all three security dimensions: attackers can achieve high-level confidentiality, integrity, and availability compromise on the underlying system. The FAUCET Risk Score of 42.0/100 indicates moderate concern, though the extremely low EPSS score (0.0023) suggests minimal real-world exploitation probability currently. EXPLOITATION STATUS There is no indication of active exploitation in the wild, as CVE-2026-35519 is not listed on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat intelligence hot lists. No public exploit code appears to be widely available, and community attention has been limited. Organizations running Pi-hole FTL versions 6.0-6.5 should prioritize patching to version 6.6 to mitigate this risk, particularly in environments where authentication access cannot be strictly controlled.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0, <= 6.5CPE matchmatch criteria | cpe:2.3:a:pi-hole:ftldns:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.