Junglewise Threat Intelligence

CVE-2026-39849: Pi-hole FTL newline injection in dns.interface configuration

CVE-2026-39849 · Severity: high · CVSS 8.8 · Published 2026-05-05

Technologies: Pi-hole FTL. Vendors: Pi-hole.

Executive brief

Pi-hole FTL is the core engine for the Pi-hole advertisement and tracker blocker. A security flaw allows an attacker on the same network to take full control of the device by injecting malicious commands into its configuration. This is particularly dangerous for installations using the default setting of no administrator password, as it allows for remote code execution without any credentials.

Technical details

A newline injection vulnerability exists in the `dns.interface` configuration field of Pi-hole FTL due to improper validation using a stub validator. An attacker can use the PATCH /api/config endpoint to inject arbitrary dnsmasq directives, such as `dhcp-script`, into the generated configuration file. While the field is limited to 31 bytes by a `strncpy` operation, this is sufficient to inject a script path. When a DHCP lease is requested on the network, the injected script is executed with the privileges of the FTL process. On default installations without an admin password, no authentication is required to reach the vulnerable API. This issue is resolved in version 6.6.1 by implementing proper newline validation.

Affected products

  • Pi-hole FTL < 6.6.1

Timeline

  • 2026-04-24: patched: Version 6.6.1 released
  • 2026-05-05: disclosed: Initial CVE publication

References

Related threats