Executive brief
A security vulnerability in the F5 BIG-IP QKView utility could allow a user with low-level access to the system to view sensitive diagnostic information. QKView is a tool used to collect configuration and performance data for troubleshooting; if exploited, this flaw could lead to the exposure of internal system details that should remain protected. This could potentially assist an attacker in planning further actions against the network infrastructure.
Technical details
An improper sanitization vulnerability exists in the F5 BIG-IP QKView utility. The root cause is a failure to properly scrub or protect sensitive data within the diagnostic files generated by the utility. A local attacker with low-privileged access can exploit this to read sensitive information contained within a QKView file. This is categorized as an information disclosure vulnerability. F5 notes that software versions which have reached End of Technical Support (EoTS) were not evaluated for this flaw.
Affected products
- F5 BIG-IP QKView All versions prior to EoTS (End of Technical Support) are impacted
Timeline
- 2026-05-13: advisory: Vulnerability published by F5 and NVD