CVE-2026-50130
CVE-2026-50130 is a high-severity vulnerability in Pi-hole with a CVSS 3.x base score of 8.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-282.
Key facts
- Severity: High (CVSS 3.x base score 8.8)
- EPSS exploit prediction: 0% (17th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-282
- Affected product: Pi-hole
- Published:
- Last modified:
Description
Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to 6.4.2, a user with code execution as the unprivileged pihole user can escalate to root by replacing /etc/pihole/logrotate. The replacement is laundered to root:root ownership by pihole-FTL-prestart.sh and then parsed as root by the daily pihole flush cron, executing firstaction shell as uid 0. This issue is fixed in version 6.4.3.
Frequently asked questions
- What is CVE-2026-50130?
- Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to 6.4.2, a user with code execution as the unprivileged pihole user can escalate to root by replacing /etc/pihole/logrotate. The replacement is laundered to root:root ownership by pihole-FTL-prestart.sh and then parsed as root by the daily pihole flush cron, executing firstaction shell as uid 0. This issue is fixed in version 6.4.3.
- How severe is CVE-2026-50130?
- CVE-2026-50130 has a CVSS 3.x base score of 8.8, rated high severity. It is exploitable over local access with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2026-50130 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (17th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-50130?
- CVE-2026-50130 affects Pi-hole. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-50130?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-50130 published?
- CVE-2026-50130 was published on 2026-07-14 and last updated on 2026-07-30.
References
- https://github.com/pi-hole/pi-hole/commit/18002bf7c6bf382fe5861d01321f427019e1be89
- https://github.com/pi-hole/pi-hole/releases/tag/v6.4.3
- https://github.com/pi-hole/pi-hole/security/advisories/GHSA-h8w9-qx2v-wrww
Affected products (1)
- cpe:2.3:a:pi-hole:pi-hole:*:*:*:*:*:*:*:*
More vulnerabilities in Pi-hole
- CVE-2025-34087 — High (CVSS 8.8): An authenticated command injection vulnerability exists in Pi-hole versions up to 3.3. When adding a domain to the…
- CVE-2020-11108 — High (CVSS 8.8): The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be…
- CVE-2019-13051 — High (CVSS 8.8): Pi-Hole 4.3 allows Command Injection.
- CVE-2024-34361 — High (CVSS 8.5): Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. A…
- CVE-2020-14162 — High (CVSS 7.8): An issue was discovered in Pi-Hole through 5.0. The local www-data user has sudo privileges to execute the pihole core…
- CVE-2020-12620 — High (CVSS 7.8): Pi-hole 4.4 allows a user able to write to /etc/pihole/dns-servers.conf to escalate privileges through command…
Other CWE-282 vulnerabilities
- CVE-2026-23514 — High (CVSS 8.8): Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access control…
- CVE-2020-10632 — High (CVSS 8.8): Inadequate folder security permissions in Emerson OpenEnterprise versions through 3.3.4 may allow modification of…
- CVE-2025-27254 — High (CVSS 8.0): CWE-282 "Improper Ownership Management" in GE Vernova EnerVista UR Setup allows Authentication Bypass. The…
- CVE-2024-39755 — High (CVSS 7.8): A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0. A specially…
- CVE-2024-37999 — High (CVSS 7.8): A vulnerability has been identified in Medicalis Workflow Orchestrator (All versions). The affected application…
- CVE-2023-0386 — High (CVSS 7.8): A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities…