Junglewise Threat Intelligence

CVE-2026-42780: F5 BIG-IP SSL Orchestrator directory traversal

CVE-2026-42780 · Severity: medium · CVSS 4.9 · Published 2026-05-13

Vendors: F5.

Executive brief

F5 BIG-IP SSL Orchestrator, a tool used to manage encrypted traffic for security inspection, contains a vulnerability that allows high-privileged users to manipulate system files. An attacker with administrative access could exploit this to delete, overwrite, or corrupt critical local files. This could lead to service disruptions, loss of configuration data, or system instability.

Technical details

A directory traversal vulnerability (CWE-22) exists in the BIG-IP SSL Orchestrator (SSLO) module. The flaw allows an authenticated attacker with high privileges to bypass directory restrictions via the network. By submitting specially crafted path sequences, the attacker can overwrite, delete, or corrupt arbitrary files on the local filesystem. While the vulnerability requires high-level authentication, it poses a significant risk to system integrity and availability. F5 has released updates for several affected branches, including 17.x and 21.x, to mitigate this issue.

Affected products

  • F5 BIG-IP SSL Orchestrator 21.0.0, 17.5.0 to 17.5.1, 17.1.0 to 17.1.3, 16.1.0, 13.0 to 13.1.3, 12.0 to 12.3.2, 11.0 to 11.4.1

Timeline

  • 2026-05-13: advisory: Initial advisory published by F5 Networks
  • 2026-05-13: disclosed: CVE-2026-42780 published to NVD

References