CVE-2026-33765

CRITICAL LAB

Pi-hole Web <6.0 savesettings.php - Command Injection

Title source: manual
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-33765. PoCs published by exploitintel.

AI-analyzed exploit summary This repository contains functional exploit code demonstrating OS command injection (CWE-78) in Pi-hole AdminLTE v5.21 via the `webtheme` parameter in `savesettings.php`. Multiple PoC scripts are provided, including semicolon, command substitution, and pipe-based injection techniques.

Description

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions prior to 6.0 have a critical OS Command Injection vulnerability in the savesettings.php file. The application takes the user-controlled $_POST['webtheme'] parameter and concatenates it directly into a system command executed via PHP's exec() function. Since the input is neither sanitized nor validated before being passed to the shell, an attacker can append arbitrary system commands to the intended pihole command. Furthermore, because the command is executed with sudo privileges, the injected commands will run with elevated (likely root) privileges. Version 6.0 patches the issue.

Exploits (1)

github WORKING POC 3 stars
by exploitintel · cpoc
https://github.com/exploitintel/eip-pocs-and-cves/tree/main/CVE-2026-33765

This repository contains functional exploit code demonstrating OS command injection (CWE-78) in Pi-hole AdminLTE v5.21 via the `webtheme` parameter in `savesettings.php`. Multiple PoC scripts are provided, including semicolon, command substitution, and pipe-based injection techniques.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Pi-hole AdminLTE v5.1 - v5.21
No auth needed
Prerequisites: Docker for lab setup · Python 3 for PoC execution
devstral-2 · analyzed Apr 08, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0025
EPSS Percentile 48.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Lab Environment

EIP LAB Lab screenshot
patched docker pull ghcr.io/exploitintel/cve-2026-33765-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2026-33765-vulnerable:latest

Details

CWE
CWE-78
Status published
Products (2)
pi-hole/web < 6.0
pi-hole/web_interface < 6.0
Published Mar 27, 2026
Tracked Since Mar 29, 2026