Junglewise Threat Intelligence

CVE-2026-41954: F5 BIG-IP sensitive information disclosure in iControl REST and tmsh

CVE-2026-41954 · Severity: medium · CVSS 4.9 · Published 2026-05-13

Technologies: F5 BIG-IP Advanced WAF, F5 Big-Ip Access Policy Manager, F5 Big-Ip Local Traffic Manager, F5 BIG-IP, F5 Big-Ip Advanced Firewall Manager. Vendors: F5.

Executive brief

A vulnerability in F5 BIG-IP networking devices could allow an authorized administrator to view sensitive system information they should not have access to. This issue affects the management interface and command-line tools used to configure the device. While an exploit requires existing administrative credentials, it could lead to the exposure of internal configuration details or other protected data.

Technical details

A sensitive information disclosure vulnerability (CWE-200) exists in an undisclosed iControl REST endpoint and the TMOS Shell (tmsh) command within F5 BIG-IP. The flaw allows an authenticated attacker assigned the 'resource administrator' role to bypass intended access restrictions and view sensitive information. The attack vector is network-based via the management interface, but requires high privileges (PR:H) to execute. Affected versions include the 16.1.x and 17.5.x branches, as well as version 21.0.0. F5 has released advisory K32950402 regarding this issue.

Affected products

  • F5 BIG-IP Access Policy Manager 16.1.0-16.1.6, 17.5.0-17.5.1, 21.0.0
  • F5 BIG-IP Advanced Firewall Manager 16.1.0-16.1.6, 17.5.0-17.5.1, 21.0.0
  • F5 BIG-IP Advanced WAF 16.1.0-16.1.6, 17.5.0-17.5.1, 21.0.0
  • F5 BIG-IP Local Traffic Manager 16.1.0-16.1.6, 17.5.0-17.5.1, 21.0.0

Timeline

  • 2026-05-13: disclosed: Initial publication date
  • 2026-05-13: advisory: F5 published advisory K32950402

References

Related threats