CVE-2026-94127

Summary

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability.

Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected Software

VendorProductVersion RangeStatus
F5BIG-IP21.1.0 < Hotfix-BIGIP-21.1.0.2.0.30.22-ENGaffected
F5BIG-IP17.5.0 < Hotfix-BIGIP-17.5.1.9.0.160.12-ENGaffected
F5BIG-IP17.1.0 < Hotfix-BIGIP-17.1.3.5.0.41.14-ENGaffected

Weaknesses

  • CWE-122: CWE-122 Heap-based Buffer Overflow

Workarounds

An iRule is available upon request. Open a ticket with F5 support to request this.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: active
    • Automatable: yes
    • Technical Impact: total

Additional References

References