← Back to CVE List
Vulnerability Intelligence Report
Pi-hole: Local privilege escalation from `pihole` user to root via `/etc/pihole/logrotate`

CVE-2026-50130

Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to 6.4.2, a user with code execution as the unprivileged pihole user can escalate to root by replacing /etc/pihole/logrotate. The replacement is laundered to root:root ownership by pihole-FTL-prestart.sh and then parsed as root by the daily pihole flush cron, executing firstaction shell as uid 0. This issue is fixed in version 6.4.3.

No Active Exploit Signals
CVSS Base Score
8.8
HIGH
Exploitability:2.1
Impact Score:6.1
EPSS Probability:0.22%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-282 ↗CWE-282: Improper Ownership Management

Affected Products & Versions

Vendor Product Affected Versions
pi-hole pi-hole >= 6.0.0, < 6.4.3 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.225%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2026-06-03T18:49:32
Published2026-07-14T21:35:00
Last Updated2026-07-16T03:55:27

LINK COPIED TO CLIPBOARD