Junglewise Threat Intelligence

CVE-2026-42919: F5 BIG-IP privilege escalation in multiple modules

CVE-2026-42919 · Severity: medium · CVSS 6.7 · Published 2026-05-13

Executive brief

A vulnerability in F5 BIG-IP systems could allow an already authenticated administrator to gain higher levels of access than intended. BIG-IP is a suite of networking products used to manage and secure enterprise application traffic. If exploited, an attacker could bypass security boundaries to perform unauthorized actions or disrupt services, potentially compromising the integrity of the network infrastructure.

Technical details

A stack-based buffer overflow (CWE-121) exists in multiple F5 BIG-IP modules, including APM, AFM, and Local Traffic Manager. The vulnerability is reachable over the network but requires high privileges (administrative access) as a precondition. An authenticated attacker can exploit this flaw to escalate their privileges and cross established security boundaries within the system. F5 has identified affected versions across the 16.x, 17.x, and 21.x branches; users are advised to consult the vendor advisory for specific patch versions.

Affected products

  • F5 BIG-IP Access Policy Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Advanced Firewall Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Advanced WAF 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Local Traffic Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0

Timeline

  • 2026-05-13: advisory: Initial publication of the vulnerability advisory

References

Related threats