Junglewise Threat Intelligence

CVE-2026-40631: F5 BIG-IP privilege escalation in iControl SOAP

CVE-2026-40631 · Severity: high · CVSS 8.7 · Published 2026-05-13

Technologies: F5 BIG-IP Advanced WAF, F5 Big-Ip Access Policy Manager, F5 Big-Ip Local Traffic Manager, F5 BIG-IP, F5 Big-Ip Advanced Firewall Manager. Vendors: F5.

Executive brief

F5 BIG-IP is a suite of networking and security solutions used to manage application traffic and protect corporate networks. A vulnerability in the management interface allows an authorized administrator with restricted permissions to bypass security controls and modify system configuration objects. This could lead to a full takeover of the device, potentially allowing an attacker to intercept traffic or disrupt critical business services.

Technical details

A privilege escalation vulnerability exists in F5 BIG-IP's iControl SOAP interface. The flaw allows authenticated users with high-level but restricted roles, such as Resource Administrator, to modify configuration objects they should not have access to. By manipulating these objects, an attacker can escalate their privileges to gain broader control over the system. The attack is reachable over the network via the management interface, though it requires valid administrative credentials. F5 has released security updates to address this issue in supported versions.

Affected products

  • F5 BIG-IP Access Policy Manager 16.1.0-16.1.6, 17.5.0-17.5.1, 21.0.0
  • F5 BIG-IP Advanced Firewall Manager 16.1.0-16.1.6, 17.5.0-17.5.1, 21.0.0
  • F5 BIG-IP Advanced WAF 16.1.0-16.1.6, 17.5.0-17.5.1, 21.0.0
  • F5 BIG-IP Local Traffic Manager 16.1.0-16.1.6, 17.5.0-17.5.1, 21.0.0

Timeline

  • 2026-05-13: advisory: Initial publication of the vulnerability advisory.

References

Related threats