CVE-2026-33765 | pi-hole web up to 5.x savesettings.php exec webtheme os command injection (GHSA-828h-5x96-rqx7)
A vulnerability was found in pi-hole web up to 5.x. It has been declared as critical. This affects the function exec of the file savesettings.php. The manipulation of the argument webtheme results in os command injection.
This vulnerability is reported as CVE-2026-33765. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.