Pi-hole released v6.4.3 to fix CVE-2026-50130, a high-severity local privilege escalation flaw affecting versions 6.0.0 through 6.4.2. The bug allowed an attacker who already had code execution as the unprivileged pihole user to gain root privileges by replacing /etc/pihole/logrotate, which was later re-owned by root and processed by a root-executed cron workflow. The issue is tracked as CWE-282 and carries a CVSS v3.1 vector of AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H.
The fix moves Pi-hole's logrotate configuration from /etc/pihole/logrotate to /etc/logrotate.d/pihole and updates related scripts, cron jobs, installer logic, debugging routines, and uninstall cleanup to use the new path. Pi-hole said the release also removes use of copytruncate in log rotation and includes additional non-security fixes and dependency updates. The vulnerability was reported by supperhellokitty20 and is referenced in GHSA-h8w9-qx2v-wrww.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-50130 was publicly documented as a local privilege escalation vulnerability affecting Pi-hole versions 6.0.0 through 6.4.2. The entry describes how a user with code execution as the unprivileged pihole user could replace /etc/pihole/logrotate and later gain root privileges through a root-executed cron workflow.
Pi-hole released version 6.4.3 as a security update fixing a high-severity local privilege escalation vulnerability that allowed escalation from the pihole user to root via /etc/pihole/logrotate. The release notes say the issue was reported by supperhellokitty20 and reference GitHub Security Advisory GHSA-h8w9-qx2v-wrww.
A Pi-hole GitHub commit changed the logrotate configuration path from /etc/pihole/logrotate to /etc/logrotate.d/pihole and updated related scripts, cron entries, installer behavior, and cleanup logic. This code change is the fix associated with the later-disclosed privilege escalation issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.