CVE-2026-94127
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Summary
When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability.
Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| F5 | BIG-IP | 21.1.0 < Hotfix-BIGIP-21.1.0.2.0.30.22-ENG | affected |
| F5 | BIG-IP | 17.5.0 < Hotfix-BIGIP-17.5.1.9.0.160.12-ENG | affected |
| F5 | BIG-IP | 17.1.0 < Hotfix-BIGIP-17.1.3.5.0.41.14-ENG | affected |
Weaknesses
- CWE-122: CWE-122 Heap-based Buffer Overflow
Workarounds
An iRule is available upon request. Open a ticket with F5 support to request this.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: active
- Automatable: yes
- Technical Impact: total
Additional References
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.