Executive brief
A vulnerability in F5 BIG-IP devices could allow a high-privileged user to download sensitive system files. These devices are commonly used to manage and secure corporate network traffic and applications. While an attacker must already have administrative access, this flaw allows them to bypass intended restrictions to access confidential data they should not be able to reach.
Technical details
A vulnerability classified as CWE-552 (Files or Directories Accessible to External Parties) exists in the iControl SOAP interface of F5 BIG-IP. The flaw allows an authenticated attacker with high privileges (Resource Administrator or Administrator roles) to bypass file access restrictions and download sensitive system files. The attack is reachable over the network via the SOAP API. While the attacker requires existing administrative credentials, the vulnerability represents a failure to properly enforce access controls on sensitive filesystem resources. F5 has released updates for affected versions including 16.1.x and 17.5.x.
Affected products
- F5 BIG-IP Access Policy Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
- F5 BIG-IP Advanced Firewall Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
- F5 BIG-IP Advanced WAF 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
- F5 BIG-IP Local Traffic Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
Timeline
- 2026-05-13: advisory: Initial publication of the vulnerability advisory