CVE-2026-41959
F5 BIG-IP Virtual Edition vulnerability analysis and mitigation

Overview

CVE-2026-41959 is an incorrect permission assignment vulnerability affecting F5 BIG-IP and BIG-IQ products in their TMOS Shell (tmsh) network diagnostics commands and BIG-IP iControl REST interface. It allows authenticated low-privilege attackers to view the network status of destination systems, constituting an unauthorized information disclosure. The vulnerability was published on May 13, 2026, and is classified as High severity with a CVSS v4 base score of 7.1 and a CVSS v3.1 base score of 6.5 (GitHub Advisory, F5 Advisory). Affected versions include BIG-IP 17.5.0 < 17.5.1.6, 17.1.0 < 17.1.3.2, 21.0.0 < 21.0.0.2, 16.1.0 and later unpatched branches, and BIG-IQ 8.4.0 and later; software versions that have reached End of Technical Support (EoTS) are not evaluated (GitHub Advisory).

Technical details

The root cause is classified as CWE-732 (Incorrect Permission Assignment for Critical Resource), where permissions on security-critical resources — specifically tmsh network diagnostics commands and iControl REST endpoints — are configured in a way that allows unintended actors to access them (GitHub Advisory). An authenticated attacker with low privileges can invoke these improperly permissioned commands or API endpoints to query the network connectivity status of destination systems without requiring elevated rights. The attack vector for iControl REST is network-based (no local access required per CVSS v4), while the CVSS v3.1 vector reflects a local attack vector with changed scope, indicating the information disclosed extends beyond the attacker's immediate privilege boundary (GitHub Advisory). No public proof-of-concept code has been identified.

Impact

Successful exploitation allows an authenticated attacker with low privileges to disclose network connectivity and status information about destination systems managed or reachable by the BIG-IP or BIG-IQ appliance. This constitutes a confidentiality breach — specifically, exposure of network topology data — with no impact to integrity or availability of the affected systems (GitHub Advisory, F5 Advisory). While the direct impact is limited to information disclosure, exposed network topology details could assist an attacker in planning further lateral movement or targeted attacks within the environment.

Exploitability

There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation of CVE-2026-41959 at this time (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.041% (16th percentile), indicating a low probability of exploitation in the near term. Exploitation requires authenticated access with low privileges, which limits the attacker pool but does not eliminate risk in environments with shared or compromised credentials.

Exploitation steps

  1. Obtain authenticated access: Acquire valid low-privilege credentials for the target BIG-IP or BIG-IQ system, either through credential theft, phishing, or use of a shared/default account.
  2. Access tmsh or iControl REST: Log in to the TMOS Shell (tmsh) via SSH or access the BIG-IP iControl REST API using the obtained credentials.
  3. Execute network diagnostics commands: Run improperly permissioned tmsh network diagnostics commands (e.g., ping, traceroute, or similar network status commands) that should be restricted to higher-privilege roles.
  4. Alternatively, query iControl REST: Send authenticated HTTP requests to iControl REST endpoints that expose network diagnostic functionality without proper permission enforcement.
  5. Collect network status information: Review the output to enumerate network connectivity, reachability, and topology of destination systems accessible from the BIG-IP/BIG-IQ appliance, which can inform further attack planning (GitHub Advisory, F5 Advisory).

Indicators of compromise

  • Logs: Audit logs in tmsh or BIG-IP showing low-privilege users executing network diagnostics commands (e.g., ping, traceroute, run util) that are atypical for their role; iControl REST access logs showing authenticated GET/POST requests to network diagnostic endpoints from unexpected user accounts or source IPs.
  • Network: Unusual outbound network probe traffic (ICMP, traceroute packets) originating from the BIG-IP management interface initiated by non-administrative sessions.
  • Authentication: Multiple low-privilege user logins to tmsh or iControl REST followed immediately by network diagnostic command execution, particularly outside of normal business hours.

Mitigation and workarounds

F5 has released patched versions addressing this vulnerability: BIG-IP 17.5.1.6 (for 17.5.0 branch), 17.1.3.2 (for 17.1.0 branch), and 21.0.0.2 (for 21.0.0 branch); BIG-IQ 8.4.0 and later branches should be reviewed against F5's advisory for applicable fixes (F5 Advisory, GitHub Advisory). As a workaround, administrators should apply the principle of least privilege to restrict authenticated user access to tmsh network diagnostics commands and iControl REST endpoints, and audit existing role assignments to ensure only authorized users have access to these functions. Monitoring and auditing of tmsh and iControl REST usage by authenticated users is also recommended.

Additional resources


SourceThis report was generated using AI

Related F5 BIG-IP Virtual Edition vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-42920HIGH8.7
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_application_security_manager
NoYesMay 13, 2026
CVE-2026-42930HIGH8.5
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesMay 13, 2026
CVE-2026-42924HIGH8.5
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_local_traffic_manager
NoYesMay 13, 2026
CVE-2026-42937HIGH7.1
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_domain_name_system
NoYesMay 13, 2026
CVE-2026-42919HIGH7.1
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesMay 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management