Junglewise Threat Intelligence

CVE-2026-40703: F5 BIG-IP CSRF in Configuration utility dashboard

CVE-2026-40703 · Severity: medium · CVSS 5.4 · Published 2026-05-13

Technologies: F5 BIG-IP. Vendors: F5.

Executive brief

A security vulnerability exists in the management dashboard of F5 BIG-IP networking devices. An attacker could trick an authenticated administrator into performing unintended actions on the device by clicking a malicious link. This could lead to unauthorized configuration changes or service disruptions on the network appliance.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability (CWE-352) exists in the F5 BIG-IP Configuration utility dashboard. The flaw allows a remote attacker to induce a victim (typically an administrator with an active session) to perform unintended actions via the web interface. The attack requires user interaction, specifically that the victim visits a malicious website or clicks a crafted link while authenticated to the BIG-IP management console. Successful exploitation can result in unauthorized configuration modifications or partial impact on system availability. F5 has released updates for affected versions, including 17.5.1.4 and later.

Affected products

  • F5 BIG-IP 17.5.0 - 17.5.1, 16.1.0 - 16.1.6

Timeline

  • 2026-05-13: disclosed
  • 2026-05-13: advisory

References

Related threats