Junglewise Threat Intelligence

CVE-2026-24464: F5 BIG-IP directory traversal in iControl REST endpoint

CVE-2026-24464 · Severity: medium · CVSS 6.8 · Published 2026-05-13

Technologies: F5 BIG-IP Advanced WAF, F5 Big-Ip Access Policy Manager, F5 Big-Ip Local Traffic Manager, F5 BIG-IP, F5 Big-Ip Advanced Firewall Manager. Vendors: F5.

Executive brief

A security vulnerability exists in F5 BIG-IP devices when they are configured in Appliance mode. This flaw allows an authorized administrator to bypass intended security restrictions and delete system files. Such an exploit could lead to service disruptions or the loss of critical configuration data, potentially impacting business continuity.

Technical details

A directory traversal vulnerability (CWE-35) exists in an undisclosed iControl REST endpoint within F5 BIG-IP. The vulnerability is specifically present when the device is running in 'Appliance mode'. An authenticated attacker with administrator-level privileges can exploit this flaw via the network to traverse the file system and delete arbitrary files. This allows the attacker to cross a security boundary that should normally restrict such file operations in Appliance mode. The issue affects multiple BIG-IP modules including LTM, APM, and AFM across versions 16.1.x, 17.5.x, and 21.0.0.

Affected products

  • F5 BIG-IP Access Policy Manager 16.1.0-16.1.6, 17.5.0-17.5.1, 21.0.0
  • F5 BIG-IP Advanced Firewall Manager 16.1.0-16.1.6, 17.5.0-17.5.1, 21.0.0
  • F5 BIG-IP Advanced WAF 16.1.0-16.1.6, 17.5.0-17.5.1, 21.0.0
  • F5 BIG-IP Local Traffic Manager 16.1.0-16.1.6, 17.5.0-17.5.1, 21.0.0

Timeline

  • 2026-05-13: disclosed

References

Related threats