Junglewise Threat Intelligence

CVE-2026-42406: F5 BIG-IP and BIG-IQ privilege escalation in configuration objects

CVE-2026-42406 · Severity: high · CVSS 8.7 · Published 2026-05-13

Technologies: F5 BIG-IQ, F5 BIG-IP. Vendors: F5.

Executive brief

F5 BIG-IP and BIG-IQ systems, which manage and secure enterprise network traffic, are affected by a security flaw. An attacker who already has high-level administrative access, specifically with the Certificate Manager role, can manipulate system settings to execute unauthorized commands. This could allow an attacker to gain full control over the device, potentially leading to data theft or significant network disruption.

Technical details

A vulnerability classified as 'Privilege Defined With Unsafe Actions' (CWE-267) exists in F5 BIG-IP and BIG-IQ systems. The flaw resides in the management interface where configuration objects can be manipulated by users holding the Certificate Manager role. An authenticated attacker with these high-level privileges can exploit this to execute arbitrary system commands, effectively escalating their privileges to root or equivalent. The attack is reachable over the network via the management interface but requires valid high-privileged credentials. F5 has released security updates to address this issue in supported versions.

Affected products

  • F5 BIG-IP 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IQ All versions prior to fix

Timeline

  • 2026-05-13: disclosed
  • 2026-05-13: advisory

References

Related threats