CVE-2026-66842: 
F5 BIG-IP Virtual Edition (tier - best) Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-66842 is a privilege escalation vulnerability in F5 BIG-IP's Traffic Management User Interface (TMUI) that allows any authenticated user, regardless of their assigned role, to create administrative user accounts via an undisclosed request. The vulnerability affects BIG-IP versions 17.1.0 through 17.1.3.4, 17.5.0 through 17.5.1.8, 21.0.0 through 21.0.0.3, and 21.1.0 through 21.1.0.1, as well as BIG-IQ versions 8.4.0 through 8.4.2.1. It was published on September 2, 2026, and is classified as a control plane issue with no data plane exposure. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, F5 Advisory).

Détails techniques

The vulnerability is classified under CWE-918 (Server-Side Request Forgery), suggesting the TMUI processes undisclosed requests in a manner that allows manipulation of internal API calls or backend services responsible for user account management. An authenticated attacker with any role — including low-privileged roles — can send a specially crafted request to the BIG-IP management interface to trigger the creation of administrative accounts, bypassing intended access controls. The specific endpoint and request structure have not been publicly disclosed by F5. No public proof-of-concept code has been released as of the time of this report (GitHub Advisory, F5 Advisory).

Impact

Successful exploitation allows a low-privileged authenticated attacker to escalate their privileges by creating new administrative accounts on the BIG-IP system, effectively gaining full control over the management plane. This could lead to unauthorized configuration changes, interception of traffic policies, credential harvesting, and persistent backdoor access via rogue admin accounts. The impact is confined to the control plane — there is no direct data plane exposure — but full administrative access to BIG-IP could enable significant downstream compromise of network infrastructure managed by the device (GitHub Advisory, F5 Advisory).

Exploitabilité

As of the publication date, there is no evidence of active in-the-wild exploitation and no public proof-of-concept exploit has been identified (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.25–0.28%, placing it in the 21st percentile for exploitation likelihood within 30 days. Exploitation requires valid credentials (any role) and network access to the BIG-IP management interface, which limits the attack surface compared to unauthenticated vulnerabilities. No threat actor attribution has been reported (GitHub Advisory).

Étapes d’exploitation

  1. Reconnaissance: Identify internet-facing or internally accessible F5 BIG-IP management interfaces (TMUI, typically on port 443 or 8443) running affected versions (17.1.0–17.1.3.3, 17.5.0–17.5.1.7, 21.0.0–21.0.0.2, 21.1.0) using tools like Shodan, Censys, or internal network scanning.
  2. Obtain low-privileged credentials: Acquire any valid BIG-IP user account credentials, regardless of role (e.g., operator, guest, or any other non-admin role). This could be achieved through phishing, credential stuffing, or insider access.
  3. Authenticate to TMUI: Log in to the BIG-IP management interface using the obtained credentials.
  4. Send undisclosed crafted request: Craft and send a specific (undisclosed) HTTP request to the TMUI that triggers the administrative account creation functionality without proper authorization checks, exploiting the SSRF-related flaw (CWE-918) in the request handling logic.
  5. Create administrative account: The crafted request results in the creation of a new administrative user account on the BIG-IP system.
  6. Escalate and persist: Log in with the newly created administrative account to gain full control of the BIG-IP management plane, modify configurations, establish persistence, or pivot to other managed network resources (GitHub Advisory, F5 Advisory).

Indicateurs de compromis

  • Logs: Audit log entries in /var/log/audit or BIG-IP audit logs showing unexpected user account creation events, particularly new accounts with Administrator role created by non-administrative users; TMUI access logs showing unusual POST requests to user management endpoints from low-privileged accounts.
  • File System: Unexpected entries in the BIG-IP user database (/config/bigip/auth/) corresponding to newly created administrative accounts not provisioned by authorized administrators.
  • Network: Unusual HTTP/HTTPS requests to the BIG-IP management interface (port 443/8443) from internal hosts that do not typically access TMUI; repeated authentication attempts followed by account management API calls.
  • Process/Behavioral: New administrative accounts appearing in the BIG-IP user list (tmsh list auth user) that were not created through standard provisioning workflows; login events from newly created admin accounts originating from unexpected source IPs (F5 Advisory).

Atténuation et solutions de contournement

F5 has released patched versions addressing this vulnerability: BIG-IP 17.1.3.4, 17.5.1.8, 21.0.0.3, and 21.1.0.1; BIG-IQ 8.4.2.1. Organizations should upgrade to these fixed versions as the primary remediation. As an immediate workaround, restrict network access to the BIG-IP management interface (TMUI) to only authorized administrators using firewall rules or management network segmentation, reducing the attack surface. Additionally, monitor audit logs for unexpected administrative account creation and review existing user accounts for unauthorized entries (F5 Advisory, GitHub Advisory).

Réactions de la communauté

The vulnerability was noted by security tracking platforms including Tenable, which published a Nessus plugin (342417) for detection shortly after disclosure. VulDB and other community trackers indexed the CVE promptly. No significant public researcher commentary, vendor statements beyond the F5 advisory, or major media coverage has been identified as of the report date (GitHub Advisory).

Ressources additionnelles


Source: Ce rapport a été généré à l’aide de l’IA

Apparenté F5 BIG-IP Virtual Edition (tier - best) Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-94127CRITICAL9.3
  • F5 BIG-IP Virtual Edition (tier - best) logoF5 BIG-IP Virtual Edition (tier - best)
  • cpe:2.3:a:f5:big-ip_access_policy_manager
OuiOuiSep 22, 2026
CVE-2026-66842HIGH8.7
  • F5 BIG-IP Virtual Edition (tier - best) logoF5 BIG-IP Virtual Edition (tier - best)
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NonOuiSep 02, 2026
CVE-2026-59762HIGH8.7
  • F5 BIG-IP Virtual Edition (tier - best) logoF5 BIG-IP Virtual Edition (tier - best)
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NonOuiJul 15, 2026
CVE-2026-42937HIGH7.1
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NonOuiMay 13, 2026
CVE-2026-63020LOW2.3
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NonOuiSep 02, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités