
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-66842 is a privilege escalation vulnerability in F5 BIG-IP's Traffic Management User Interface (TMUI) that allows any authenticated user, regardless of their assigned role, to create administrative user accounts via an undisclosed request. The vulnerability affects BIG-IP versions 17.1.0 through 17.1.3.4, 17.5.0 through 17.5.1.8, 21.0.0 through 21.0.0.3, and 21.1.0 through 21.1.0.1, as well as BIG-IQ versions 8.4.0 through 8.4.2.1. It was published on September 2, 2026, and is classified as a control plane issue with no data plane exposure. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, F5 Advisory).
The vulnerability is classified under CWE-918 (Server-Side Request Forgery), suggesting the TMUI processes undisclosed requests in a manner that allows manipulation of internal API calls or backend services responsible for user account management. An authenticated attacker with any role — including low-privileged roles — can send a specially crafted request to the BIG-IP management interface to trigger the creation of administrative accounts, bypassing intended access controls. The specific endpoint and request structure have not been publicly disclosed by F5. No public proof-of-concept code has been released as of the time of this report (GitHub Advisory, F5 Advisory).
Successful exploitation allows a low-privileged authenticated attacker to escalate their privileges by creating new administrative accounts on the BIG-IP system, effectively gaining full control over the management plane. This could lead to unauthorized configuration changes, interception of traffic policies, credential harvesting, and persistent backdoor access via rogue admin accounts. The impact is confined to the control plane — there is no direct data plane exposure — but full administrative access to BIG-IP could enable significant downstream compromise of network infrastructure managed by the device (GitHub Advisory, F5 Advisory).
As of the publication date, there is no evidence of active in-the-wild exploitation and no public proof-of-concept exploit has been identified (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.25–0.28%, placing it in the 21st percentile for exploitation likelihood within 30 days. Exploitation requires valid credentials (any role) and network access to the BIG-IP management interface, which limits the attack surface compared to unauthenticated vulnerabilities. No threat actor attribution has been reported (GitHub Advisory).
/var/log/audit or BIG-IP audit logs showing unexpected user account creation events, particularly new accounts with Administrator role created by non-administrative users; TMUI access logs showing unusual POST requests to user management endpoints from low-privileged accounts./config/bigip/auth/) corresponding to newly created administrative accounts not provisioned by authorized administrators.tmsh list auth user) that were not created through standard provisioning workflows; login events from newly created admin accounts originating from unexpected source IPs (F5 Advisory).F5 has released patched versions addressing this vulnerability: BIG-IP 17.1.3.4, 17.5.1.8, 21.0.0.3, and 21.1.0.1; BIG-IQ 8.4.2.1. Organizations should upgrade to these fixed versions as the primary remediation. As an immediate workaround, restrict network access to the BIG-IP management interface (TMUI) to only authorized administrators using firewall rules or management network segmentation, reducing the attack surface. Additionally, monitor audit logs for unexpected administrative account creation and review existing user accounts for unauthorized entries (F5 Advisory, GitHub Advisory).
The vulnerability was noted by security tracking platforms including Tenable, which published a Nessus plugin (342417) for detection shortly after disclosure. VulDB and other community trackers indexed the CVE promptly. No significant public researcher commentary, vendor statements beyond the F5 advisory, or major media coverage has been identified as of the report date (GitHub Advisory).
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"