CVE-2026-33765Disclosure(pi-hole / web_interface)

LOWCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for pi-hole web_interface systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions prior to 6.0 have a critical OS Command Injection vulnerability in the savesettings.php file. The application takes the user-controlled $_POST['webtheme'] parameter and concatenates it directly into a system command executed via PHP's exec() function. Since the input is neither sanitized nor validated before being passed to the shell, an attacker can append arbitrary system commands to the intended pihole command. Furthermore, because the command is executed with sudo privileges, the injected commands will run with elevated (likely root) privileges. Version 6.0 patches the issue.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • web_interface

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-28); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
web_interface

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-28: 2Mentions · 2026-03-29: 1Active Exploitation · 2026-03-29: 103-2803-29
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Active Exploitation
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-282
Disclosure1General1
2026-03-291
Active Exploitation1
Full discourse3 posts
  • VulDB 🛡@vuldb
    Active Exploitation

    Attention, elevated activities detected targeting pi-hole web (CVE-2026-33765) https://vuldb.com/vuln/353983/cti

    Post summary

    The post alerts to active exploitation of CVE-2026-33765 against pi-hole web services, but offers no technical detail, PoC, or patch info.

    0000058
    2.1K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for pi-hole web (CVE-2026-33765) https://vuldb.com/vuln/353983

    Post summary

    A severe CVE‑2026‑33765 affecting pi‑hole web has been disclosed and referenced via VulDB, but no additional technical details, PoC, exploits, patches, or exploitation reports are provided.

    0000055
    2.1K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-33765 Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions prior to 6.0 have a critical O… https://www.cve.org/CVERecord?id=CVE-2026-33765

    Post summary

    The post merely lists CVE-2026-33765 with a brief, incomplete note that it is a critical issue in Pi‑hole Admin Interface, offering no further details or actionable information.

    00000190
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppi-holeweb_interface---

Explore more