CVE-2026-41489 - Pi-hole: Local privilege escalation via config-controlled path in root-executed service hooks
CVE ID :CVE-2026-41489 Published : May 11, 2026, 8:21 p.m. | 44 minutes ago Description :Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to before Core 6.4.2 and FTL 6.6.1, two shell scripts executed as root by systemd
ORIGINAL SOURCE →via CVE Feed Latest
ADVERTISEMENT
⚡ STAY AHEAD
Events like this, convergence-verified across 689 sources, land in your inbox every Sunday. Free.
GET THE SUNDAY BRIEFING →RELATED · cyber
- [CYBER] Nvidia GeForce NOW data breach confirmed — but luckily most of us will be safe, here's why
- [CYBER] Linux bitten by second severe vulnerability in as many weeks
- [CYBER] Simandou ships record quantity of iron ore, swelling Chinese stocks
- [CYBER] Anthropic's Bug-Hunting Mythos Was Greatest Marketing Stunt Ever, Says cURL Creator
- [CYBER] CVE-2026-43874 - WWBN AVideo: Incomplete Fix for YPTSocket autoEvalCodeOnHTML Strip: Unauthenticated Cross-User JavaScript Execution via `$msg['json']` Relay Bypass
- [CYBER] CVE-2026-8321 - inkeep agents runAuth Middleware runAuth.ts createDevContext authentication bypass