Junglewise Threat Intelligence

CVE-2026-40462: F5 BIG-IP incorrect permission assignment in iControl REST and tmsh

CVE-2026-40462 · Severity: medium · CVSS 6.5 · Published 2026-05-13

Technologies: F5 BIG-IP Advanced WAF, F5 Big-Ip Access Policy Manager, F5 Big-Ip Local Traffic Manager, F5 BIG-IP, F5 Big-Ip Advanced Firewall Manager, F5 iControl REST. Vendors: F5.

Executive brief

A security vulnerability has been identified in F5 BIG-IP networking devices, which are used to manage and secure corporate web traffic. An authenticated user with low-level access could exploit a flaw in certain management commands to view sensitive system information they are not authorized to see. This could lead to the exposure of configuration details or other internal data, potentially aiding further attacks on the network infrastructure.

Technical details

This vulnerability (CWE-732) stems from incorrect permission assignments within the iControl REST interface and the TMOS shell (tmsh) for an undisclosed command. An attacker must be authenticated to the system, but only requires low-level privileges to execute the affected command. Successful exploitation allows the attacker to bypass intended access controls and read sensitive system information. The issue affects multiple BIG-IP modules including APM, AFM, and Local Traffic Manager across versions 16.1.x, 17.5.x, and 21.0.0. F5 has released advisory K000156581 to address the issue; users should consult the vendor for specific patch versions.

Affected products

  • F5 BIG-IP Access Policy Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Advanced Firewall Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Advanced WAF 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Local Traffic Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0

Timeline

  • 2026-05-13: advisory: Initial publication of the vulnerability advisory.

References

Related threats