Junglewise Threat Intelligence

CVE-2026-41959: F5 BIG-IP and BIG-IQ incorrect permission assignment in tmsh and iControl REST

CVE-2026-41959 · Severity: medium · CVSS 6.5 · Published 2026-05-13

Technologies: F5 BIG-IQ, F5 BIG-IP. Vendors: F5.

Executive brief

F5 BIG-IP and BIG-IQ networking devices contain a security flaw in their diagnostic tools and management interfaces. An authorized user with low-level access could exploit this to view sensitive network status information about other systems they should not be able to see. This could lead to unauthorized reconnaissance of the internal network environment.

Technical details

An incorrect permission assignment vulnerability (CWE-732) exists in the TMOS Shell (tmsh) network diagnostics commands and the iControl REST interface. The flaw allows an authenticated attacker with low privileges to execute diagnostic utilities that reveal the network status of destination systems. On BIG-IP, the vulnerability affects both the command-line shell and the REST API, while on BIG-IQ it affects the shell commands. Attackers can leverage this to perform internal network discovery. F5 has released updates for affected BIG-IP versions (16.x, 17.x, and 21.x).

Affected products

  • F5 BIG-IP 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IQ All versions (EoTS excluded)

Timeline

  • 2026-05-13: advisory: Initial publication of the advisory by F5

References

Related threats