Junglewise Threat Intelligence

CVE-2026-40699: F5 BIG-IP XPath injection in Configuration utility

CVE-2026-40699 · Severity: medium · CVSS 6.5 · Published 2026-05-13

Technologies: F5 Big-Ip Access Policy Manager, F5 Big-Ip Local Traffic Manager, F5 BIG-IP, F5 Big-Ip Advanced Firewall Manager, F5 BIG-IP DNS. Vendors: F5.

Executive brief

A vulnerability in the F5 BIG-IP Configuration utility could allow a user with low-level access to view sensitive system information they are not authorized to see. This utility is used by administrators to manage network traffic and security settings. An exploit could lead to the exposure of internal configuration details, potentially aiding further attacks against the organization's network infrastructure.

Technical details

An XPath injection vulnerability (CWE-643) exists within undisclosed pages of the F5 BIG-IP Configuration utility. The flaw is caused by improper neutralization of data within XPath expressions, which can be triggered by an authenticated attacker with low-level privileges. By sending specially crafted requests over the network to the management interface, an attacker can bypass intended access controls to retrieve sensitive configuration data. The vulnerability affects multiple BIG-IP modules including LTM, APM, AFM, and DNS across versions 16.1.x and 17.5.x. F5 has provided mitigation guidance in advisory K000156734.

Affected products

  • F5 BIG-IP Access Policy Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1
  • F5 BIG-IP Advanced Firewall Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1
  • F5 BIG-IP Advanced Web Application Firewall 16.1.0 - 16.1.6, 17.5.0 - 17.5.1
  • F5 BIG-IP Local Traffic Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1
  • F5 BIG-IP DNS 16.1.0 - 16.1.6, 17.5.0 - 17.5.1

Timeline

  • 2026-05-13: advisory: Initial publication of the vulnerability details.
  • 2026-06-24: other: NVD last modified date.

References

Related threats