CVE-2026-35520 | pi-hole FTL up to 6.5 Web Interface dhcp.leaseTime os command injection
A vulnerability labeled as critical has been found in pi-hole FTL up to 6.5. Affected by this vulnerability is an unknown functionality of the component Web Interface. The manipulation of the argument dhcp.leaseTime results in os command injection.
This vulnerability is identified as CVE-2026-35520. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.