
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-42937 is an incorrect permission assignment vulnerability affecting F5 BIG-IP and BIG-IQ products, specifically in the TMOS Shell (tmsh) arp and ndp commands and in BIG-IP iControl REST. The vulnerability allows an authenticated attacker with low privileges to view adjacent network information that should be restricted to higher privilege levels. It was published on May 13, 2026, with a patch made available the same day. Affected versions include BIG-IP 16.1.0 and later (up to fixed versions), BIG-IP 17.1.0 < 17.1.3.2, BIG-IP 17.5.0 < 17.5.1.6, BIG-IP 21.0.0 < 21.0.0.2, and BIG-IQ 8.4.0 and later. The CVSS v3.1 base score is 6.5 (Medium) and the CVSS v4.0 base score is 7.1 (High) (GitHub Advisory, F5 Advisory).
The root cause is classified as CWE-732 (Incorrect Permission Assignment for Critical Resource), where the arp and ndp commands in the BIG-IP/BIG-IQ TMOS Shell and the iControl REST API are configured with permissions that allow lower-privileged authenticated users to access information intended only for higher-privileged roles. An attacker with valid, low-privilege credentials can invoke these commands or REST endpoints over the network without any user interaction, obtaining adjacent network topology data such as ARP and NDP table entries. No special attack complexity or prerequisites beyond valid credentials are required (GitHub Advisory, F5 Advisory).
Successful exploitation results in unauthorized disclosure of adjacent network information, including ARP and NDP table data, which could reveal network topology, IP-to-MAC address mappings, and neighboring device details. There is no integrity or availability impact — the vulnerability is limited to confidentiality. While the scope is constrained to adjacent network information, this data could assist an attacker in further reconnaissance or lateral movement within the network environment (GitHub Advisory, F5 Advisory).
arp or ndp commands within tmsh, or issue equivalent iControl REST API requests (e.g., GET /mgmt/tm/net/arp or GET /mgmt/tm/net/ndp) that should be restricted to higher-privilege roles.arp or ndp commands in tmsh; iControl REST access logs recording GET requests to /mgmt/tm/net/arp or /mgmt/tm/net/ndp by accounts not expected to access these endpoints.F5 has released patched versions: BIG-IP 17.1.3.2, 17.5.1.6, and 21.0.0.2. Organizations should upgrade to these fixed versions as the primary remediation. As an interim workaround, restrict access to tmsh arp and ndp commands and iControl REST endpoints to only users who legitimately require access to adjacent network information, and audit user role assignments to enforce least-privilege principles (F5 Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."