Executive brief
F5 BIG-IP is a critical network appliance that manages traffic and security for enterprise networks. An authenticated user can exploit an undisclosed request to the management web interface to create administrative accounts and escalate privileges, potentially giving an attacker full control of the system. This is a control-plane vulnerability only; production traffic handling is not directly affected, but compromise of the management interface is a complete loss of system integrity.
Technical details
This is a privilege escalation vulnerability in the BIG-IP Traffic Management User Interface (TMUI). An authenticated user of any role can send a specially crafted request to the TMUI to create new administrative user accounts, bypassing normal role-based access controls. The vulnerability requires network access to the BIG-IP management interface and valid authentication credentials (any user role), but allows immediate privilege escalation to administrative level. An attacker can gain full administrative control of the BIG-IP system, enabling system reconfiguration, policy bypass, or denial of service. Patch status and specific affected versions are not disclosed in this advisory.
Affected products
- F5 BIG-IP <UNKNOWN>
Timeline
- 2026-09-02: disclosed