Junglewise Threat Intelligence

CVE-2026-32643: F5 BIG-IP and BIG-IQ privilege escalation in Certificate Manager role

CVE-2026-32643 · Severity: high · CVSS 8.7 · Published 2026-05-13

Technologies: F5 Big-Iq Centralized Management, F5 BIG-IQ, F5 Big-Ip Access Policy Manager, F5 Big-Ip Local Traffic Manager, F5 BIG-IP, F5 Big-Ip Advanced Firewall Manager, F5 BIG-IP Advanced WAF. Vendors: F5.

Executive brief

F5 BIG-IP and BIG-IQ systems, which are used to manage and secure enterprise network traffic, contain a vulnerability that could allow a highly privileged user to take full control of the system. An attacker who already has administrative access, specifically with the Certificate Manager role, can bypass intended restrictions to run unauthorized commands. This could lead to a complete compromise of the device, potentially impacting all network traffic and security policies managed by the appliance.

Technical details

A vulnerability classified as 'Execution with Unnecessary Privileges' (CWE-250) exists in F5 BIG-IP and BIG-IQ systems. The flaw allows a highly privileged, authenticated attacker—specifically one assigned at least the Certificate Manager role—to modify configuration objects in a way that facilitates arbitrary command execution. The attack vector is network-based and requires high privileges (PR:H) but no user interaction. Successful exploitation results in a scope change (S:C), allowing the attacker to move from the restricted management role to full system execution. F5 has released advisory K000160972 to address this issue across multiple product modules including LTM, APM, and AFM.

Affected products

  • F5 BIG-IP Access Policy Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Advanced Firewall Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Advanced WAF 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Local Traffic Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IQ Centralized Management Not specified

Timeline

  • 2026-05-13: advisory: Initial publication of the vulnerability advisory

References

Related threats