← Vulnerability feed

Vulnerability record · CVE-2021-29449 · published 14 April 2021

CVE-2021-29449: Pi-hole improper privilege management vulnerability

Pi Hole · Pi Hole

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation vulnerabilities were discovered in version 5.2.4 of Pi-hole core. See the referenced GitHub security advisory for details.

7.8 CVSS 3.1 High EPSS 1.8% · top 21.8% CWE-269 · Improper privilege managementCWE-78 · OS command injection
7.8CVSS 3.1 base score, v2 7.2
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
7References, 7 tagged exploit
17 Jun 2026Last modified by NVD

Description

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation vulnerabilities were discovered in version 5.2.4 of Pi-hole core. See the referenced GitHub security advisory for details.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-29449 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.2CVE-2020-8816Pi-hole AdminLTE DHCP static lease OS command injectionPi-hole Web v4.3.2 (AdminLTE) fails to sanitize the MAC address field of a DHCP static lease, allowing OS command injection. A privileged dashboard u…KEVEPSS 78%analysed9.0CVE-2025-34087Pi-hole os command injection vulnerabilityAn authenticated command injection vulnerability exists in Pi-hole versions up to 3.3. When adding a domain to the allowlist via the web interface, t…EPSS 7.0%8.8CVE-2026-50130Pi-hole vulnerabilityPi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to 6.4.2, a user with cod…EPSS 0.26%8.8CVE-2024-34361Pi-hole server-side request forgery (ssrf) vulnerabilityPi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. A vulnerability in versions prior …EPSS 2.8%8.8CVE-2021-32706Pi-hole Web interface regex filter flaw enables code injectionPi-hole Web interface before version 5.5.1 has an unescaped period in the validDomainWildcard preg_match filter, allowing a malicious character to pa…EPSS 60%analysed8.8CVE-2021-29448Pi-hole ftldns cross-site scripting vulnerabilityPi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Admin portal, which ca…EPSS 0.67%8.8CVE-2020-11108Pi-hole Gravity updater unrestricted file upload leads to RCEThe Gravity updater in Pi-hole through 4.4 contains a code error in gravity_DownloadBlocklistFromUrl in gravity.sh that lets an authenticated user up…EPSS 78%analysed8.8CVE-2019-13051Pi-hole os command injection vulnerabilityPi-Hole 4.3 allows Command Injection.EPSS 12%

Source: NIST National Vulnerability Database (record CVE-2021-29449), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.