CVE-2026-44693

HIGH

Pi-hole FTL: Unauthenticated Session Hijacking via Race Condition on Global Session Buffer

Title source: cna
STIX 2.1

Description

Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. Prior to version 6.6.1, Pi-hole FTL contains a race condition vulnerability in the HTTP session management subsystem, introduced with the v6.0 rewrite of the embedded CivetWeb-based web server. This issue has been patched in version 6.6.1.

References (2)

Core 2
Core References
X_Refsource_Misc x_refsource_misc
https://github.com/pi-hole/FTL/releases/tag/v6.6.1

Scores

CVSS v3 8.8
EPSS 0.0023
EPSS Percentile 13.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-362
Status published
Products (1)
pi-hole/FTL < 6.6.1
Published Jun 10, 2026
Tracked Since Jun 11, 2026