LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-41489

CVE-2026-41489 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: May 12, 2026

Pi-hole - Privilege Escalation

Published: May 11, 2026Updated: May 12, 2026

Overview

Pi-hole 6.0 to before Core 6.4.2 and FTL 6.6.1 contains a local privilege escalation caused by unvalidated file path usage in root-executed shell scripts, letting attackers with pihole privilege gain root write access via file manipulation, exploit requires pihole privilege.

Severity & Score

Severity: High
CVSS Score: 8.8

Impact

Attackers with pihole privilege can gain root access by manipulating files, leading to full system compromise.

Mitigation

Update to Core 6.4.2 and FTL 6.6.1 or later.

Details

CVE ID
CVE-2026-41489
Severity
High
CVSS Score
8.8
Type
broken_access_control
Status
rejected

CWE

  • CWE-15

CVSS Metrics

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H