Executive brief
A vulnerability in F5 BIG-IP devices allows a highly privileged user, such as a Manager, to execute unauthorized commands on the system. This could lead to a complete takeover of the device, potentially compromising network traffic management and security policies. While the attacker needs existing administrative access, this flaw allows them to bypass intended restrictions and gain full control over the underlying operating system.
Technical details
This vulnerability is classified as an Incorrect Use of Privileged APIs (CWE-648) within the iControl REST interface of F5 BIG-IP. An authenticated attacker with 'Manager' or higher privileges can exploit this by creating specific configuration objects that trigger the execution of arbitrary system commands. The attack is reachable over the network but requires high privileges (PR:H). Successful exploitation results in a full compromise of the device's confidentiality, integrity, and availability, with a scope change (S:C) indicating impact beyond the iControl REST component itself. Affected versions include branches 16.1.x, 17.5.x, and 21.0.0.
Affected products
- F5 BIG-IP Access Policy Manager 16.1.0-16.1.6, 17.5.0-17.5.1, 21.0.0
- F5 BIG-IP Advanced Firewall Manager 16.1.0-16.1.6, 17.5.0-17.5.1, 21.0.0
- F5 BIG-IP Advanced WAF 16.1.0-16.1.6, 17.5.0-17.5.1, 21.0.0
- F5 BIG-IP Local Traffic Manager 16.1.0-16.1.6, 17.5.0-17.5.1, 21.0.0
Timeline
- 2026-05-13: disclosed
- 2026-05-13: advisory