Junglewise Threat Intelligence

CVE-2026-20916: F5 BIG-IQ path traversal in iControl REST

CVE-2026-20916 · Severity: high · CVSS 8.1 · Published 2026-05-13

Technologies: F5 Big-Iq Centralized Management, F5 BIG-IQ. Vendors: F5.

Executive brief

F5 BIG-IQ is a centralized management platform used to administer and orchestrate F5 network devices. A security flaw allows a user with low-level access to create or change files across the system. This could lead to service disruptions or unauthorized system modifications, potentially impacting the stability and integrity of the network management infrastructure.

Technical details

A path traversal vulnerability (CWE-22) exists in an undisclosed iControl REST endpoint within F5 BIG-IQ Centralized Management. An authenticated attacker with low-level privileges can exploit this flaw via the network to create or modify arbitrary files on the filesystem. While the vulnerability does not directly allow data exfiltration (Confidentiality: None), it poses a high risk to system integrity and availability. The issue affects version 8.4.0 and is addressed in version 8.4.1.

Affected products

  • F5 BIG-IQ Centralized Management 8.4.0

Timeline

  • 2026-05-13: advisory: Initial advisory published by F5 and NVD

References

Related threats