CVE-2026-50130CWE-282

Pi-hole: Local privilege escalation from `pihole` user to root via `/etc/pihole/logrotate`

High · published July 14, 2026

CVSS v3.1
8.8
EPSS
0%
Percentile
16.5
In the wild
Unconfirmed
What it is

Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to 6.4.2, a user with code execution as the unprivileged pihole user can escalate to root by replacing /etc/pihole/logrotate. The replacement is laundered to root:root ownership by pihole-FTL-prestart.sh and then parsed as root by the daily pihole flush cron, executing firstaction shell as uid 0. This issue is fixed in version 6.4.3.

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00252 · 16.5th percentile
Weakness
CWE-282 · Improper Ownership Management
Published
2026-07-14T21:35Z
EPSS history
Timeline
  • 14 JUL 21:35Z
    Pi-hole: Local privilege escalation from `pihole` user to root via `/etc/pihole/logrotate`
    cvelistv5