CVE-2026-35518 | pi-hole FTL up to 6.5 Web Interface dns.cnameRecords os command injection
A vulnerability classified as critical was found in pi-hole FTL up to 6.5. The affected element is an unknown function of the component Web Interface. Executing a manipulation of the argument dns.cnameRecords can lead to os command injection.
This vulnerability appears as CVE-2026-35518. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.