CVE-2026-42937
F5 BIG-IP Virtual Edition vulnerability analysis and mitigation

Overview

CVE-2026-42937 is an incorrect permission assignment vulnerability affecting F5 BIG-IP and BIG-IQ products, specifically in the TMOS Shell (tmsh) arp and ndp commands and in BIG-IP iControl REST. The vulnerability allows an authenticated attacker with low privileges to view adjacent network information that should be restricted to higher privilege levels. It was published on May 13, 2026, with a patch made available the same day. Affected versions include BIG-IP 16.1.0 and later (up to fixed versions), BIG-IP 17.1.0 < 17.1.3.2, BIG-IP 17.5.0 < 17.5.1.6, BIG-IP 21.0.0 < 21.0.0.2, and BIG-IQ 8.4.0 and later. The CVSS v3.1 base score is 6.5 (Medium) and the CVSS v4.0 base score is 7.1 (High) (GitHub Advisory, F5 Advisory).

Technical details

The root cause is classified as CWE-732 (Incorrect Permission Assignment for Critical Resource), where the arp and ndp commands in the BIG-IP/BIG-IQ TMOS Shell and the iControl REST API are configured with permissions that allow lower-privileged authenticated users to access information intended only for higher-privileged roles. An attacker with valid, low-privilege credentials can invoke these commands or REST endpoints over the network without any user interaction, obtaining adjacent network topology data such as ARP and NDP table entries. No special attack complexity or prerequisites beyond valid credentials are required (GitHub Advisory, F5 Advisory).

Impact

Successful exploitation results in unauthorized disclosure of adjacent network information, including ARP and NDP table data, which could reveal network topology, IP-to-MAC address mappings, and neighboring device details. There is no integrity or availability impact — the vulnerability is limited to confidentiality. While the scope is constrained to adjacent network information, this data could assist an attacker in further reconnaissance or lateral movement within the network environment (GitHub Advisory, F5 Advisory).

Exploitation steps

  1. Obtain valid credentials: Acquire low-privilege authenticated credentials for a BIG-IP or BIG-IQ system running an affected version (e.g., through phishing, credential stuffing, or insider access).
  2. Access tmsh or iControl REST: Log in to the TMOS Shell (tmsh) via SSH or access the iControl REST API endpoint using the obtained credentials.
  3. Execute restricted commands: Run the arp or ndp commands within tmsh, or issue equivalent iControl REST API requests (e.g., GET /mgmt/tm/net/arp or GET /mgmt/tm/net/ndp) that should be restricted to higher-privilege roles.
  4. Collect adjacent network information: Review the output, which reveals ARP/NDP table entries including IP addresses, MAC addresses, and interface associations of adjacent network devices.
  5. Use data for further reconnaissance: Leverage the disclosed network topology information to identify additional targets or plan lateral movement within the network (GitHub Advisory, F5 Advisory).

Indicators of compromise

  • Logs: BIG-IP audit logs showing low-privilege user accounts executing arp or ndp commands in tmsh; iControl REST access logs recording GET requests to /mgmt/tm/net/arp or /mgmt/tm/net/ndp by accounts not expected to access these endpoints.
  • Network: Unusual or repeated REST API queries to ARP/NDP endpoints from authenticated sessions associated with low-privilege service or operator accounts.
  • Behavioral: Low-privilege user accounts accessing network information commands outside of normal administrative workflows or at unusual times.

Mitigation and workarounds

F5 has released patched versions: BIG-IP 17.1.3.2, 17.5.1.6, and 21.0.0.2. Organizations should upgrade to these fixed versions as the primary remediation. As an interim workaround, restrict access to tmsh arp and ndp commands and iControl REST endpoints to only users who legitimately require access to adjacent network information, and audit user role assignments to enforce least-privilege principles (F5 Advisory, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related F5 BIG-IP Virtual Edition vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-42920HIGH8.7
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesMay 13, 2026
CVE-2026-42930HIGH8.5
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesMay 13, 2026
CVE-2026-42924HIGH8.5
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_application_security_manager
NoYesMay 13, 2026
CVE-2026-42937HIGH7.1
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesMay 13, 2026
CVE-2026-42919HIGH7.1
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesMay 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management