Junglewise Threat Intelligence

CVE-2026-35062: F5 BIG-IP information disclosure in iControl SOAP interface

CVE-2026-35062 · Severity: medium · CVSS 6.5 · Published 2026-05-13

Technologies: F5 BIG-IP Advanced WAF, F5 Big-Ip Access Policy Manager, F5 Big-Ip Local Traffic Manager, F5 BIG-IP, F5 Big-Ip Advanced Firewall Manager. Vendors: F5.

Executive brief

F5 BIG-IP networking and security appliances are affected by a vulnerability that allows an authorized user to view information belonging to other user accounts. This issue impacts the iControl SOAP interface, which is used for automated management and configuration of the device. An attacker with existing low-level access could exploit this to gain sensitive details about other administrators or system users, potentially aiding in further unauthorized activities.

Technical details

A vulnerability classified as Incorrect Privilege Assignment (CWE-266) exists in the F5 BIG-IP iControl SOAP interface. An authenticated attacker with network access to the management interface can leverage this flaw to retrieve account information for other users on the system. The vulnerability affects multiple BIG-IP modules including APM, AFM, and LTM across versions 16.1.x, 17.5.x, and 21.0.0. Exploitation requires valid credentials but does not require high-level administrative privileges. F5 has released a vendor advisory (K000159021) detailing the affected versions and necessary mitigations.

Affected products

  • F5 BIG-IP Access Policy Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Advanced Firewall Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Advanced WAF 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Local Traffic Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0

Timeline

  • 2026-05-13: advisory: Initial publication of the vulnerability advisory.

References

Related threats