
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-42924 is a privilege escalation vulnerability in F5 BIG-IP affecting the iControl SOAP interface. An authenticated attacker holding the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP, resulting in privilege escalation beyond their authorized level. The vulnerability was published on May 13, 2026, and affects BIG-IP versions 17.1.0 before 17.1.3.1, 17.5.0 before 17.5.1.4, 21.0.0 before 21.0.0.1, and all 16.1.0 branch versions; software versions that have reached End of Technical Support (EoTS) are not evaluated. It carries a CVSS v4.0 base score of 8.5 (High) and a CVSS v3.1 base score of 8.7 (High) (GitHub Advisory, F5 Advisory).
The root cause is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command / OS Command Injection), where user-supplied input passed through the iControl SOAP API is not properly sanitized before being used in OS-level operations. An authenticated attacker with the Resource Administrator or Administrator role can craft SNMP configuration object creation requests via iControl SOAP that inject malicious OS command elements, ultimately escalating their privileges on the BIG-IP system. The attack vector is network-based, requires no user interaction, and has low attack complexity, though it does require high-privilege credentials as a precondition. No public proof-of-concept exploit code has been identified at this time (GitHub Advisory, F5 Advisory).
Successful exploitation allows an authenticated attacker to escalate privileges beyond their assigned role on the BIG-IP system, resulting in high confidentiality and high integrity impact to the vulnerable system. An attacker who gains elevated privileges could access sensitive configuration data, modify system settings, and potentially pivot to other network resources managed by the BIG-IP appliance. Availability is not directly impacted by this vulnerability, but the integrity and confidentiality compromise of a network appliance like BIG-IP could have significant downstream consequences for the infrastructure it manages (GitHub Advisory, F5 Advisory).
/var/log/audit) showing SNMP configuration object creation by Resource Administrator or Administrator accounts at unusual times or from unexpected source IPs; iControl SOAP access logs with anomalous request payloads.F5 has released patched versions addressing this vulnerability: BIG-IP 17.1.3.1, 17.5.1.4, and 21.0.0.1. Administrators should upgrade to these versions as the primary remediation (F5 Advisory). As interim workarounds, restrict access to the iControl SOAP interface to trusted management hosts only using BIG-IP management port access controls or firewall rules. Additionally, limit assignment of the Resource Administrator and Administrator roles to only personnel who strictly require them, and monitor SNMP configuration object creation activities for unauthorized changes.
The Hacker Wire published a technical article covering the iControl SOAP privilege escalation via SNMP configuration creation shortly after disclosure (The Hacker Wire). The vulnerability was also noted in the CTIPILOT threat intelligence brief for May 17, 2026, alongside other F5 BIG-IP vulnerabilities disclosed in the same advisory cycle. Community reaction has been measured, consistent with the lack of public exploit code and the requirement for pre-existing high-privilege credentials.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."