CVE-2026-35519 | pi-hole FTL up to 6.5 Web Interface dns.hostRecord os command injection
A vulnerability identified as critical has been detected in pi-hole FTL up to 6.5. Affected is an unknown function of the component Web Interface. The manipulation of the argument dns.hostRecord leads to os command injection.
This vulnerability is referenced as CVE-2026-35519. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.