CVE-2026-35517 | pi-hole FTL up to 6.5 Web Interface dns.upstreams os command injection
A vulnerability classified as critical has been found in pi-hole FTL up to 6.5. Impacted is an unknown function of the component Web Interface. Performing a manipulation of the argument dns.upstreams results in os command injection.
This vulnerability is reported as CVE-2026-35517. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.