Pi-Hole · Pi-Hole · CVE-2026-33727
**Name of the Vulnerable Software and Affected Versions**
Pi-hole version 6.4
**Description**
A local privilege-escalation issue allows code execution as root from the low-privilege `pihole` account. While the `pihole` account uses nologin, which prevents direct interactive login, code can still run under the `pihole` UID if a component is compromised. In such a scenario, an attacker can place controlled content in the `/etc/pihole/versions` file, which is then sourced by scripts running with root privileges, resulting in root code execution.
**Recommendations**
Update Pi-hole to version 6.4.1.