Executive brief
A vulnerability in F5 BIG-IP systems allows an administrator to bypass 'Appliance mode' security restrictions. Appliance mode is a hardened state designed to limit access to the underlying operating system for sensitive environments. An exploit could allow a high-privileged user to gain unauthorized access to system-level functions, potentially compromising the integrity of the device and the data it protects.
Technical details
A path traversal vulnerability (CWE-35) in F5 BIG-IP allows authenticated users with the 'Administrator' role to bypass Appliance mode restrictions. Appliance mode is intended to restrict access to the bash shell and other sensitive system-level utilities. By exploiting this flaw, an attacker can circumvent these hardening measures to interact with the underlying operating system. The vulnerability affects multiple BIG-IP modules including LTM, APM, and AFM across versions 16.1.x, 17.5.x, and 21.0.0. F5 has released advisory K000160876 to address this issue.
Affected products
- F5 BIG-IP Access Policy Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
- F5 BIG-IP Advanced Firewall Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
- F5 BIG-IP Advanced WAF 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
- F5 BIG-IP Local Traffic Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
Timeline
- 2026-05-13: advisory: Initial publication of the vulnerability advisory