« Volver al listado

CVE-2026-44693

Estado: AplazadaAlta (8.8)—

Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. Prior to version 6.6.1, Pi-hole FTL contains a race condition vulnerability in the HTTP session management subsystem, introduced with the v6.0 rewrite of the embedded CivetWeb-based web server. This issue has been patched in version 6.6.1.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector CVSS con UI:R y acceso remoto (AV:N) → T1203 (ejecución en cliente). Race condition en sesión HTTP permite escalada a privilegios elevados (T1068) y posible ejecución de comandos en servidor Pi-hole (T1059).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (2)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-44693",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-44693",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-11T00:00:00+00:00"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "pi-hole",
          "product": "FTL",
          "versions": [
            {
              "status": "affected",
              "version": "< 6.6.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-06-10T23:16:46.690",
  "references": [
    {
      "url": "https://github.com/pi-hole/FTL/releases/tag/v6.6.1",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/pi-hole/FTL/security/advisories/GHSA-9ff5-f3v5-2xc7",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/pi-hole/FTL/security/advisories/GHSA-9ff5-f3v5-2xc7",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-362"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. Prior to version 6.6.1, Pi-hole FTL contains a race condition vulnerability in the HTTP session management subsystem, introduced with the v6.0 rewrite of the embedded CivetWeb-based web server. This issue has been patched in version 6.6.1."
    },
    {
      "lang": "es",
      "value": "Pi-hole FTL es el motor principal del bloqueador de anuncios y rastreadores a nivel de red de Pi-hole. Antes de la versión 6.6.1, Pi-hole FTL contiene una vulnerabilidad de condición de carrera en el subsistema de gestión de sesiones HTTP, introducida con la reescritura v6.0 del servidor web embebido basado en CivetWeb. Este problema ha sido parcheado en la versión 6.6.1."
    }
  ],
  "lastModified": "2026-07-23T09:10:00.113",
  "sourceIdentifier": "security-advisories@github.com"
}