
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20730 is an information disclosure vulnerability (CWE-200) affecting F5 BIG-IP Edge Client and browser VPN clients on Windows. It allows a low-privileged local attacker to gain access to sensitive information without user interaction. Affected products include BIG-IP Access Policy Manager (APM) versions 16.1.0–16.1.6, 17.1.0–17.1.3.0, and 17.5.0–17.5.1, as well as BIG-IP Access Policy Manager Client versions 7.2.5 through 7.2.6.1. The vulnerability was published on February 4, 2026, with a patch made available on February 13, 2026. It carries a CVSS v3.1 base score of 3.3 (Low) and a CVSS v4.0 base score of 2.0 (Low) (F5 Advisory).
The vulnerability is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), arising from improper protection of sensitive data within the BIG-IP Edge Client and browser VPN client processes on Windows. An attacker with low-level local privileges can read sensitive information — such as VPN credentials or connection configuration details — from the client application without requiring user interaction. Exploitation requires local access and the presence of specific conditions (CVSS attack requirements: Present), limiting the attack surface to authenticated local users on affected Windows systems. No public proof-of-concept or technical write-up detailing the precise exploitation mechanism has been published (F5 Advisory, Feedly).
Successful exploitation allows an authenticated local attacker with low privileges to read sensitive information from the BIG-IP Edge Client or browser VPN clients, potentially exposing VPN credentials, session tokens, or connection configuration details. The vulnerability has no impact on data integrity or system availability, and its scope is limited to the local system without lateral movement capability inherent to the flaw itself. However, exposed VPN credentials could be leveraged by an attacker for subsequent unauthorized network access (F5 Advisory).
F5 has released patches addressing this vulnerability. Users should upgrade to the following fixed versions:
Software versions that have reached End of Technical Support (EoTS) are not evaluated. As interim mitigations, restrict local system access to authorized users only, apply the principle of least privilege to limit low-privilege account access to VPN client processes, and monitor for unauthorized access attempts on affected systems (F5 Advisory).
Coverage of CVE-2026-20730 was largely bundled with F5's broader February 2026 security update cycle, which addressed more critical vulnerabilities in BIG-IP and NGINX products. Security news outlets including CyberSecurityNews, GBHackers, and Heise covered the F5 patch release, though focus was primarily on higher-severity issues in the same advisory batch. No notable individual researcher commentary or significant community discussion specific to this low-severity CVE has been observed (CyberSecurityNews, GBHackers, Heise).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."