CVE-2026-42924
F5 BIG-IP Virtual Edition vulnerability analysis and mitigation

Overview

CVE-2026-42924 is a privilege escalation vulnerability in F5 BIG-IP affecting the iControl SOAP interface. An authenticated attacker holding the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP, resulting in privilege escalation beyond their authorized level. The vulnerability was published on May 13, 2026, and affects BIG-IP versions 17.1.0 before 17.1.3.1, 17.5.0 before 17.5.1.4, 21.0.0 before 21.0.0.1, and all 16.1.0 branch versions; software versions that have reached End of Technical Support (EoTS) are not evaluated. It carries a CVSS v4.0 base score of 8.5 (High) and a CVSS v3.1 base score of 8.7 (High) (GitHub Advisory, F5 Advisory).

Technical details

The root cause is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command / OS Command Injection), where user-supplied input passed through the iControl SOAP API is not properly sanitized before being used in OS-level operations. An authenticated attacker with the Resource Administrator or Administrator role can craft SNMP configuration object creation requests via iControl SOAP that inject malicious OS command elements, ultimately escalating their privileges on the BIG-IP system. The attack vector is network-based, requires no user interaction, and has low attack complexity, though it does require high-privilege credentials as a precondition. No public proof-of-concept exploit code has been identified at this time (GitHub Advisory, F5 Advisory).

Impact

Successful exploitation allows an authenticated attacker to escalate privileges beyond their assigned role on the BIG-IP system, resulting in high confidentiality and high integrity impact to the vulnerable system. An attacker who gains elevated privileges could access sensitive configuration data, modify system settings, and potentially pivot to other network resources managed by the BIG-IP appliance. Availability is not directly impacted by this vulnerability, but the integrity and confidentiality compromise of a network appliance like BIG-IP could have significant downstream consequences for the infrastructure it manages (GitHub Advisory, F5 Advisory).

Exploitation steps

  1. Obtain Credentials: Acquire valid credentials for a BIG-IP account with the Resource Administrator or Administrator role, either through phishing, credential stuffing, or insider access.
  2. Identify Target: Locate an internet-facing or network-accessible F5 BIG-IP instance running a vulnerable version (e.g., 17.1.0–17.1.3.0, 17.5.0–17.5.1.3, 21.0.0, or 16.1.x) using network scanning or Shodan.
  3. Access iControl SOAP Interface: Authenticate to the BIG-IP iControl SOAP API endpoint (typically accessible via HTTPS on the management interface).
  4. Craft Malicious SNMP Configuration Request: Send a specially crafted SOAP request to create an SNMP configuration object, embedding OS command injection payloads within the object parameters that are not properly sanitized.
  5. Achieve Privilege Escalation: The injected OS commands execute with elevated privileges on the BIG-IP system, allowing the attacker to perform actions beyond their assigned role, such as accessing sensitive data or modifying critical system configurations (GitHub Advisory, F5 Advisory).

Indicators of compromise

  • Network: Unusual or unexpected SOAP API calls to the BIG-IP iControl SOAP endpoint from non-standard management hosts; SNMP configuration object creation requests originating from accounts not typically performing such actions.
  • Logs: BIG-IP audit logs (/var/log/audit) showing SNMP configuration object creation by Resource Administrator or Administrator accounts at unusual times or from unexpected source IPs; iControl SOAP access logs with anomalous request payloads.
  • Process: Unexpected OS-level processes spawned by the BIG-IP management plane (e.g., shell commands, network utilities) that are not part of normal BIG-IP operations.
  • Configuration: Unauthorized or unexpected changes to SNMP configuration objects in the BIG-IP running configuration; new or modified SNMP community strings, trap destinations, or user accounts.

Mitigation and workarounds

F5 has released patched versions addressing this vulnerability: BIG-IP 17.1.3.1, 17.5.1.4, and 21.0.0.1. Administrators should upgrade to these versions as the primary remediation (F5 Advisory). As interim workarounds, restrict access to the iControl SOAP interface to trusted management hosts only using BIG-IP management port access controls or firewall rules. Additionally, limit assignment of the Resource Administrator and Administrator roles to only personnel who strictly require them, and monitor SNMP configuration object creation activities for unauthorized changes.

Community reactions

The Hacker Wire published a technical article covering the iControl SOAP privilege escalation via SNMP configuration creation shortly after disclosure (The Hacker Wire). The vulnerability was also noted in the CTIPILOT threat intelligence brief for May 17, 2026, alongside other F5 BIG-IP vulnerabilities disclosed in the same advisory cycle. Community reaction has been measured, consistent with the lack of public exploit code and the requirement for pre-existing high-privilege credentials.

Additional resources


SourceThis report was generated using AI

Related F5 BIG-IP Virtual Edition vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-42920HIGH8.7
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesMay 13, 2026
CVE-2026-42930HIGH8.5
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesMay 13, 2026
CVE-2026-42924HIGH8.5
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_application_security_manager
NoYesMay 13, 2026
CVE-2026-42937HIGH7.1
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesMay 13, 2026
CVE-2026-42919HIGH7.1
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesMay 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management