Junglewise Threat Intelligence

CVE-2026-41217: F5 BIG-IP privilege escalation in TMOS Shell command

CVE-2026-41217 · Severity: high · CVSS 7.9 · Published 2026-05-13

Technologies: F5 Big-Ip Access Policy Manager, F5 Big-Ip Local Traffic Manager, F5 Big-Ip Advanced Firewall Manager. Vendors: F5.

Executive brief

A vulnerability in F5 BIG-IP networking appliances could allow a high-privileged user to bypass security restrictions and execute unauthorized system commands. This affects the TMOS Shell (tmsh), a command-line interface used for managing the device's configuration. If exploited, an attacker who already has administrative access could gain even deeper control over the underlying operating system, potentially compromising the integrity of the entire network appliance.

Technical details

A privilege escalation vulnerability exists in an undisclosed command within the F5 BIG-IP TMOS Shell (tmsh). The flaw allows an authenticated user with 'Resource Administrator' or 'Administrator' roles to execute arbitrary system commands with higher privileges than intended. In 'Appliance mode' deployments, which are designed to restrict access to the underlying Linux operating system, this vulnerability allows an attacker to cross a security boundary and gain unauthorized OS-level access. The vulnerability is tracked as CVE-2026-41217 and has a CVSS score of 7.9 (3.1) or 8.3 (4.0) depending on the metric version used. F5 has released updates for affected versions including 16.x and 17.x branches.

Affected products

  • F5 BIG-IP Access Policy Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Advanced Firewall Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Advanced Web Application Firewall 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Local Traffic Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0

Timeline

  • 2026-05-13: disclosed: Initial publication date

References

Related threats