Junglewise Threat Intelligence

CVE-2026-34176: F5 BIG-IP command injection in iControl REST Appliance mode

CVE-2026-34176 · Severity: high · CVSS 8.7 · Published 2026-05-13

Technologies: F5 BIG-IP Advanced WAF, F5 Big-Ip Access Policy Manager, F5 Big-Ip Local Traffic Manager, F5 BIG-IP, F5 Big-Ip Advanced Firewall Manager. Vendors: F5.

Executive brief

F5 BIG-IP devices, which manage and secure enterprise network traffic, are vulnerable to a command injection flaw when configured in Appliance mode. An attacker with administrative credentials can execute unauthorized system commands through the management interface. This could allow a malicious actor to bypass security restrictions and gain full control over the device's operating system.

Technical details

An authenticated remote command injection vulnerability (CWE-78) exists in an undisclosed iControl REST endpoint within F5 BIG-IP. The vulnerability is specific to devices running in 'Appliance mode,' a restricted configuration intended to limit administrative access to the underlying operating system. An attacker with high-privileged credentials can exploit this flaw via the network to execute arbitrary OS commands. This allows the attacker to cross the security boundary established by Appliance mode, potentially leading to full system compromise. The issue affects multiple BIG-IP modules including LTM, APM, and AFM across versions 16.1.x, 17.5.x, and 21.0.x.

Affected products

  • F5 BIG-IP Access Policy Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Advanced Firewall Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Advanced WAF 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Local Traffic Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0

Timeline

  • 2026-05-13: advisory: Initial publication of the vulnerability advisory

References

Related threats