Executive brief
A vulnerability in F5 BIG-IP management interfaces allows a highly privileged user, such as a Manager, to bypass security restrictions and execute unauthorized commands on the system. BIG-IP devices are critical networking appliances used for traffic management, security, and access control in enterprise environments. An exploit could allow an internal attacker to gain full control over the device, potentially leading to data interception or significant network disruption.
Technical details
A least privilege violation (CWE-272) exists in the iControl REST API and the TMOS Shell (tmsh) of F5 BIG-IP. The flaw allows an authenticated user with high-level privileges (specifically the 'Manager' role or higher) to create configuration objects that trigger the execution of arbitrary system commands. While the attack requires high privileges, it allows an attacker to escalate their functional impact to full system compromise. The vulnerability affects multiple BIG-IP modules including LTM, APM, and Advanced WAF across versions 16.1.x, 17.5.x, and 21.0.0. F5 has released a vendor advisory (K000160863) detailing the issue.
Affected products
- F5 BIG-IP Access Policy Manager 16.1.0-16.1.6, 17.5.0-17.5.1, 21.0.0
- F5 BIG-IP Advanced Firewall Manager 16.1.0-16.1.6, 17.5.0-17.5.1, 21.0.0
- F5 BIG-IP Advanced WAF 16.1.0-16.1.6, 17.5.0-17.5.1, 21.0.0
- F5 BIG-IP Local Traffic Manager 16.1.0-16.1.6, 17.5.0-17.5.1, 21.0.0
Timeline
- 2026-05-13: advisory: Initial publication of the vulnerability details.