CVE-2026-66842

Summary

BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI).

Impact:

This vulnerability may allow an authenticated attacker with network access to the BIG-IP management interface to escalate privileges by creating administrative accounts on the BIG-IP system. There is no data plane exposure; this is a control plane issue only.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected Software

VendorProductVersion RangeStatus
F5BIG-IP21.1.0 < 21.1.0.1affected
F5BIG-IP21.0.0 < 21.0.0.3affected
F5BIG-IP17.5.0 < 17.5.1.8affected
F5BIG-IP17.1.0 < 17.1.3.4affected
F5BIG-IQ8.4.0 < 8.4.2.1affected

Weaknesses

  • CWE-918: CWE-918 Server-Side Request Forgery (SSRF)

Workarounds

None

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References