Junglewise Threat Intelligence

CVE-2026-42408: F5 BIG-IP sensitive information disclosure in tmsh command

CVE-2026-42408 · Severity: medium · CVSS 4.4 · Published 2026-05-13

Technologies: F5 Big-Ip Access Policy Manager, F5 Big-Ip Local Traffic Manager, F5 Big-Ip Advanced Firewall Manager, F5 BIG-IP DNS. Vendors: F5.

Executive brief

A vulnerability in F5 BIG-IP systems with DNS provisioned could allow a highly privileged user to access sensitive information they should not be able to see. This occurs through a specific administrative command-line tool used for system configuration. While the attacker must already have high-level access, this flaw could lead to the exposure of internal system secrets or configuration data.

Technical details

A cleartext storage of sensitive information vulnerability (CWE-312) exists in an undisclosed TMOS Shell (tmsh) command within F5 BIG-IP. The flaw is specifically present when BIG-IP DNS is provisioned. An authenticated attacker with high privileges can execute this command via a local attack vector to disclose sensitive system information. The vulnerability affects multiple BIG-IP modules including DNS, APM, AFM, and LTM across versions 16.1.x and 17.5.x. F5 has released security advisory K000157981 to address this issue; users are advised to consult the vendor for specific patch versions or mitigations.

Affected products

  • F5 BIG-IP DNS 17.5.0 - 17.5.1, 16.1.0 - 16.1.6
  • F5 BIG-IP Access Policy Manager 17.5.0 - 17.5.1, 16.1.0 - 16.1.6
  • F5 BIG-IP Advanced Firewall Manager 17.5.0 - 17.5.1, 16.1.0 - 16.1.6
  • F5 BIG-IP Local Traffic Manager 17.5.0 - 17.5.1, 16.1.0 - 16.1.6

Timeline

  • 2026-05-13: advisory
  • 2026-05-13: disclosed

References

Related threats