
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-41959 is an incorrect permission assignment vulnerability affecting F5 BIG-IP and BIG-IQ products in their TMOS Shell (tmsh) network diagnostics commands and BIG-IP iControl REST interface. It allows authenticated low-privilege attackers to view the network status of destination systems, constituting an unauthorized information disclosure. The vulnerability was published on May 13, 2026, and is classified as High severity with a CVSS v4 base score of 7.1 and a CVSS v3.1 base score of 6.5 (GitHub Advisory, F5 Advisory). Affected versions include BIG-IP 17.5.0 < 17.5.1.6, 17.1.0 < 17.1.3.2, 21.0.0 < 21.0.0.2, 16.1.0 and later unpatched branches, and BIG-IQ 8.4.0 and later; software versions that have reached End of Technical Support (EoTS) are not evaluated (GitHub Advisory).
The root cause is classified as CWE-732 (Incorrect Permission Assignment for Critical Resource), where permissions on security-critical resources — specifically tmsh network diagnostics commands and iControl REST endpoints — are configured in a way that allows unintended actors to access them (GitHub Advisory). An authenticated attacker with low privileges can invoke these improperly permissioned commands or API endpoints to query the network connectivity status of destination systems without requiring elevated rights. The attack vector for iControl REST is network-based (no local access required per CVSS v4), while the CVSS v3.1 vector reflects a local attack vector with changed scope, indicating the information disclosed extends beyond the attacker's immediate privilege boundary (GitHub Advisory). No public proof-of-concept code has been identified.
Successful exploitation allows an authenticated attacker with low privileges to disclose network connectivity and status information about destination systems managed or reachable by the BIG-IP or BIG-IQ appliance. This constitutes a confidentiality breach — specifically, exposure of network topology data — with no impact to integrity or availability of the affected systems (GitHub Advisory, F5 Advisory). While the direct impact is limited to information disclosure, exposed network topology details could assist an attacker in planning further lateral movement or targeted attacks within the environment.
There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation of CVE-2026-41959 at this time (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.041% (16th percentile), indicating a low probability of exploitation in the near term. Exploitation requires authenticated access with low privileges, which limits the attacker pool but does not eliminate risk in environments with shared or compromised credentials.
ping, traceroute, run util) that are atypical for their role; iControl REST access logs showing authenticated GET/POST requests to network diagnostic endpoints from unexpected user accounts or source IPs.F5 has released patched versions addressing this vulnerability: BIG-IP 17.5.1.6 (for 17.5.0 branch), 17.1.3.2 (for 17.1.0 branch), and 21.0.0.2 (for 21.0.0 branch); BIG-IQ 8.4.0 and later branches should be reviewed against F5's advisory for applicable fixes (F5 Advisory, GitHub Advisory). As a workaround, administrators should apply the principle of least privilege to restrict authenticated user access to tmsh network diagnostics commands and iControl REST endpoints, and audit existing role assignments to ensure only authorized users have access to these functions. Monitoring and auditing of tmsh and iControl REST usage by authenticated users is also recommended.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."