Junglewise Threat Intelligence

CVE-2026-40698: F5 BIG-IP and BIG-IQ privilege escalation in SNMP configuration

CVE-2026-40698 · Severity: high · CVSS 8.7 · Published 2026-05-13

Technologies: F5 BIG-IQ, F5 BIG-IP. Vendors: F5.

Executive brief

F5 BIG-IP and BIG-IQ systems, which are used to manage and secure enterprise network traffic, are affected by a privilege escalation vulnerability. An authorized user with administrative rights can manipulate system configuration settings to gain even higher levels of control over the device. This could allow an internal attacker to bypass security restrictions, potentially leading to full system compromise and unauthorized access to sensitive network data.

Technical details

A privilege escalation vulnerability exists in F5 BIG-IP and BIG-IQ systems due to improper neutralization of special elements used in a command (command injection) within SNMP configuration object creation. An authenticated attacker with at least the Resource Administrator role can exploit this via the iControl REST interface or the TMOS shell (tmsh). By creating specifically crafted SNMP configuration objects, the attacker can execute commands with elevated privileges, potentially gaining full control of the underlying system. The vulnerability is tracked as CVE-2026-40698 and has been assigned a CVSS score of 8.7. F5 has released security advisories and patches for affected versions, though software that has reached End of Technical Support was not evaluated.

Affected products

  • F5 BIG-IP 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IQ All versions

Timeline

  • 2026-05-13: advisory: Initial publication of the vulnerability advisory

References

Related threats