Junglewise Threat Intelligence

CVE-2026-40435: F5 BIG-IP unprotected endpoints in httpd IP access restrictions

CVE-2026-40435 · Severity: medium · CVSS 5.3 · Published 2026-05-13

Technologies: F5 BIG-IP. Vendors: F5.

Executive brief

F5 BIG-IP devices, which manage and secure network traffic, contain a flaw in how they restrict access based on IP addresses. This vulnerability could allow unauthorized users from blocked locations to connect to certain internal management endpoints. While it does not allow full control of the system, it could lead to the exposure of sensitive configuration information.

Technical details

A vulnerability classified as Unprotected Alternate Channel (CWE-420) exists in the httpd configuration of F5 BIG-IP. When IP-based access restrictions are configured, they fail to cover all available endpoints, allowing a remote attacker to bypass these filters and reach specific internal services. An attacker can exploit this to establish connections from IP addresses that should otherwise be blocked, potentially leading to information disclosure. The issue affects multiple BIG-IP modules including APM, AFM, and ASM. F5 has released updates (e.g., 17.5.1.4) to address this behavior.

Affected products

  • F5 BIG-IP 17.5.0 - 17.5.1, 16.1.0 - 16.1.6

Timeline

  • 2026-05-13: disclosed
  • 2026-05-13: advisory

References

Related threats