Vulnerability Intelligence Report
Pi-hole: Local privilege escalation from `pihole` user to root via `/etc/pihole/logrotate`
CVE-2026-50130
Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to 6.4.2, a user with code execution as the unprivileged pihole user can escalate to root by replacing /etc/pihole/logrotate. The replacement is laundered to root:root ownership by pihole-FTL-prestart.sh and then parsed as root by the daily pihole flush cron, executing firstaction shell as uid 0. This issue is fixed in version 6.4.3.
No Active Exploit Signals
CVSS Base Score
8.8
HIGH
Exploitability:2.1
Impact Score:6.1
EPSS Probability:0.22%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-282 ↗CWE-282: Improper Ownership Management
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| pi-hole | pi-hole | >= 6.0.0, < 6.4.3 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.225%
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | GitHub, Inc. · Vendor · USA |
| Reserved | 2026-06-03T18:49:32 |
| Published | 2026-07-14T21:35:00 |
| Last Updated | 2026-07-16T03:55:27 |
Community Chatter & Buzz