
PEACH
Un cadre d’isolation des locataires
CVE-2026-63020 is a UI misrepresentation/spoofing vulnerability in the F5 BIG-IP Configuration utility that allows an unauthenticated remote attacker to craft malicious links that reflect spoofed error messages in an authenticated user's browser session. It was published on September 2, 2026, and affects BIG-IP versions 17.1.0–17.1.3, 17.5.0–17.5.1, 21.0.0, and 21.1.0 across a broad range of BIG-IP product modules. The vulnerability is strictly a control plane issue with no data plane exposure. It carries a CVSS v4.0 base score of 2.3 (Low) and a CVSS v3.1 base score of 3.1 (Low) (GitHub Advisory, F5 Advisory).
The vulnerability is classified as CWE-451 (User Interface Misrepresentation of Critical Information), where the BIG-IP Configuration utility fails to properly validate or sanitize input used to render error messages on an undisclosed page. An attacker can craft a specially formed URL that, when visited by an authenticated BIG-IP administrator, causes the utility to reflect a spoofed error message within the victim's active browser session — a form of reflected content injection. Exploitation requires high attack complexity and passive user interaction (the victim must follow a malicious link), and no privileges are required on the attacker's side. No public technical write-ups or proof-of-concept code have been identified (GitHub Advisory, F5 Advisory).
The primary impact is a low-severity integrity issue: an attacker can display misleading or false error messages within the BIG-IP Configuration utility session of an authenticated user, potentially facilitating phishing or social engineering attacks against administrators. There is no confidentiality impact, no availability impact, and no data plane exposure — the vulnerability is confined entirely to the control plane. Lateral movement or data exfiltration are not directly enabled by this vulnerability (GitHub Advisory, F5 Advisory).
There is no evidence of active in-the-wild exploitation or publicly available proof-of-concept code for CVE-2026-63020. The EPSS score is approximately 0.186% (8th percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported. Exploitation requires tricking an authenticated BIG-IP user into clicking a crafted link, adding a meaningful social engineering barrier (GitHub Advisory, F5 Advisory).
F5 has released patched versions addressing this vulnerability: BIG-IP 17.1.3.4, 17.5.1.8, 21.0.0.3, and 21.1.0.1. Organizations should upgrade to these fixed versions as the primary remediation. As a workaround, restrict access to the BIG-IP Configuration utility to trusted management networks only, and train administrators to verify the legitimacy of any links directing them to the Configuration utility before clicking. Software versions that have reached End of Technical Support (EoTS) are not evaluated and should be upgraded (F5 Advisory, GitHub Advisory).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."