PT-2026-20953 · Pi-Hole · Pi-Hole

T0X1Cx

·

Published

2026-02-19

·

Updated

2026-03-12

·

CVE-2026-26952

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Pi-hole versions 6.4 and below
Description Pi-hole Admin Interface, a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application, is susceptible to stored HTML injection through the local DNS records configuration page. An authenticated administrator can inject code that is stored in the Pi-hole configuration and rendered when the DNS records table is viewed. The populateDataTable() function includes a data variable containing the full DNS record value, which is directly inserted into the data-tag HTML attribute without proper escaping or sanitization. An attacker can exploit this by supplying a value containing double quotes (") to prematurely close the data-tag attribute and inject additional HTML attributes. The impact is limited due to Pi-hole’s Content Security Policy (CSP) that blocks inline JavaScript.
Recommendations Update to version 6.4.1 or later.

Exploit

Fix

XSS

RCE

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

CVE-2026-26952
GHSA-6XP4-JW73-F4QP

Affected Products

Pi-Hole