Executive brief
A vulnerability in F5 BIG-IP networking appliances allows high-privileged users, such as Resource Administrators, to gain even higher levels of control over the system. By creating specific network monitoring (SNMP) configuration objects, an attacker can bypass intended restrictions to escalate their privileges. This could allow an internal attacker to gain full administrative control, potentially leading to unauthorized access to sensitive data or the ability to modify critical network traffic settings.
Technical details
A privilege escalation vulnerability exists in F5 BIG-IP's iControl SOAP interface. The flaw allows authenticated users with high-level administrative roles (Resource Administrator or Administrator) to create SNMP configuration objects that bypass standard security boundaries. This is classified as an OS Command Injection (CWE-78) issue, where the creation of these objects can be leveraged to execute unauthorized commands or escalate privileges to a higher level than intended. The attack is reachable over the network via the iControl SOAP API. F5 has released updates for affected versions including 16.x and 17.x branches; users are advised to consult the vendor advisory for specific patch versions.
Affected products
- F5 BIG-IP Access Policy Manager 16.1.0-16.1.6, 17.5.0-17.5.1, 21.0.0
- F5 BIG-IP Advanced Firewall Manager 16.1.0-16.1.6, 17.5.0-17.5.1, 21.0.0
- F5 BIG-IP Advanced WAF 16.1.0-16.1.6, 17.5.0-17.5.1, 21.0.0
- F5 BIG-IP Local Traffic Manager 16.1.0-16.1.6, 17.5.0-17.5.1, 21.0.0
Timeline
- 2026-05-13: disclosed
- 2026-05-13: advisory