← Vulnerability feed

Vulnerability record · CVE-2021-32706 · published 4 August 2021

CVE-2021-32706: Pi-hole Web interface regex filter flaw enables code injection

Pi Hole · Pi Hole

Pi-hole Web interface before version 5.5.1 has an unescaped period in the validDomainWildcard preg_match filter, allowing a malicious character to pass through. This permits code execution, directory listing, and overwriting of sensitive files. The flaw is a code injection issue in a widely used DNS management interface.

8.8 CVSS 3.1 High EPSS 60% · top 0.9% CWE-94 · Code injection
8.8CVSS 3.1 base score, v2 6.5
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prior to Pi-hole Web interface version 5.5.1, the `validDomainWildcard` preg_match filter allows a malicious character through that can be used to execute code, list directories, and overwrite sensitive files. The issue lies in the fact that one of the periods is not escaped, allowing any character to be used in its place. A patch for this vulnerability was released in version 5.5.1.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityCVSS score is 8.8 (HIGH) and EPSS is 0.60181 with an Exploit reference, but no KEV listing and exploitation requires authentication.

What it is

Pi-hole Web interface before version 5.5.1 has an unescaped period in the validDomainWildcard preg_match filter, allowing a malicious character to pass through. This permits code execution, directory listing, and overwriting of sensitive files. The flaw is a code injection issue in a widely used DNS management interface.

Impact

An authenticated attacker can execute arbitrary code, list directories, and overwrite sensitive files on the Pi-hole host. This can lead to full compromise of the Pi-hole instance and its underlying system.

Attack surface

The vulnerability is reachable over the network through the Pi-hole Web interface. The CVSS vector indicates low privileges are required and no user interaction is needed.

Exploitation

No CISA KEV listing. EPSS probability is 0.60181 (99th percentile), indicating high likelihood of exploitation. References include an Exploit tag, suggesting public exploit information exists.

What to do

  • Upgrade Pi-hole Web interface to version 5.5.1 or later immediately.
  • Restrict network access to the Pi-hole Web interface to trusted administrators only.
  • Enforce strong authentication and least privilege for Pi-hole administrative accounts.
  • Monitor for unexpected file modifications or command execution on Pi-hole hosts.
  • Review and harden any custom domain wildcard configurations.

Detection

  • Monitor web server logs for requests containing unusual characters in domain wildcard parameters.
  • Alert on unexpected file writes or directory listings in Pi-hole web directories.
  • Use file integrity monitoring on sensitive Pi-hole configuration and system files.
  • Audit Pi-hole admin user activity for anomalous commands or file operations.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-32706 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.2CVE-2020-8816Pi-hole AdminLTE DHCP static lease OS command injectionPi-hole Web v4.3.2 (AdminLTE) fails to sanitize the MAC address field of a DHCP static lease, allowing OS command injection. A privileged dashboard u…KEVEPSS 78%analysed9.0CVE-2025-34087Pi-hole os command injection vulnerabilityAn authenticated command injection vulnerability exists in Pi-hole versions up to 3.3. When adding a domain to the allowlist via the web interface, t…EPSS 7.0%8.8CVE-2026-50130Pi-hole vulnerabilityPi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to 6.4.2, a user with cod…EPSS 0.26%8.8CVE-2024-34361Pi-hole server-side request forgery (ssrf) vulnerabilityPi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. A vulnerability in versions prior …EPSS 2.8%8.8CVE-2021-29448Pi-hole ftldns cross-site scripting vulnerabilityPi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Admin portal, which ca…EPSS 0.67%8.8CVE-2020-11108Pi-hole Gravity updater unrestricted file upload leads to RCEThe Gravity updater in Pi-hole through 4.4 contains a code error in gravity_DownloadBlocklistFromUrl in gravity.sh that lets an authenticated user up…EPSS 78%analysed8.8CVE-2019-13051Pi-hole os command injection vulnerabilityPi-Hole 4.3 allows Command Injection.EPSS 12%7.8CVE-2021-29449Pi-hole improper privilege management vulnerabilityPi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation vulnerabilities were discover…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2021-32706), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.