Junglewise Threat Intelligence

CVE-2026-42058: F5 BIG-IP information leak in iControl REST

CVE-2026-42058 · Severity: medium · CVSS 4.3 · Published 2026-05-13

Technologies: F5 BIG-IP Advanced WAF, F5 Big-Ip Access Policy Manager, F5 Big-Ip Local Traffic Manager, F5 BIG-IP, F5 Big-Ip Advanced Firewall Manager. Vendors: F5.

Executive brief

A vulnerability in F5 BIG-IP networking devices could allow an authorized user to view the names of other local user accounts on the system. BIG-IP is a suite of application delivery and security services used to manage and protect corporate network traffic. While this does not allow an attacker to take over the system or access customer data directly, it provides them with valid usernames that could be used to launch more targeted password-guessing or social engineering attacks.

Technical details

An information disclosure vulnerability exists in the F5 BIG-IP iControl REST interface due to incorrect permission assignment for critical resources (CWE-732). An authenticated attacker with network access to the iControl REST interface can send specially crafted, undisclosed requests to reveal the names of local user accounts. This vulnerability requires low privileges (PR:L) and no user interaction. The leaked information (usernames) can be used to facilitate further reconnaissance or brute-force attacks against the management plane. The issue affects multiple BIG-IP modules including LTM, APM, and AFM across versions 16.1.x, 17.5.x, and 21.0.0.

Affected products

  • F5 BIG-IP Access Policy Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Advanced Firewall Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Advanced WAF 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Local Traffic Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0

Timeline

  • 2026-05-13: disclosed
  • 2026-05-13: advisory

References

Related threats