
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-66842 is a privilege escalation vulnerability in F5 BIG-IP's Traffic Management User Interface (TMUI) that allows any authenticated user, regardless of their assigned role, to create administrative user accounts via an undisclosed request. The vulnerability affects BIG-IP versions 17.1.0 < 17.1.3.4, 17.5.0 < 17.5.1.8, 21.0.0 < 21.0.0.3, and 21.1.0 < 21.1.0.1, as well as BIG-IQ versions 8.4.0 < 8.4.2.1. It was published on September 2, 2026, with a patch made available the same day. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, F5 Advisory).
The vulnerability is classified under CWE-918 (Server-Side Request Forgery), suggesting the TMUI processes undisclosed requests in a way that allows manipulation of internal API calls or backend services to perform privileged operations such as account creation. An authenticated attacker with any role — including low-privileged roles — can send a specially crafted request to the BIG-IP management interface over the network to trigger the creation of administrative accounts. No user interaction is required, and attack complexity is low, making this straightforward to exploit once authenticated. The specific endpoint and request structure have not been publicly disclosed by F5, limiting immediate PoC development (GitHub Advisory, F5 Advisory).
Successful exploitation allows any authenticated user to escalate their privileges by creating new administrative accounts on the BIG-IP system, effectively granting full control over the device's management plane. This impacts confidentiality, integrity, and availability of the BIG-IP control plane — an attacker with admin access could alter traffic policies, intercept or redirect network traffic, disable security controls, or establish persistent backdoor accounts. F5 explicitly notes this is a control plane issue only with no data plane exposure, meaning traffic forwarding functions are not directly impacted, but compromise of the management interface can have severe downstream consequences for network infrastructure (GitHub Advisory, F5 Advisory).
As of the time of publication, there is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.25–0.28%, placing it in the 20th percentile for exploitation likelihood within 30 days. The NVD SSVC assessment also rates exploitation as "none" at this time. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
POST requests to TMUI user management endpoints in BIG-IP access logs; authentication events from newly created accounts not provisioned by administrators./config/bigip/auth/ or equivalent); changes to user role assignments not initiated by known administrators.F5 has released patched versions addressing this vulnerability: BIG-IP 17.1.3.4, 17.5.1.8, 21.0.0.3, and 21.1.0.1; BIG-IQ 8.4.2.1. Organizations should upgrade to these versions immediately. As a workaround, restrict network access to the BIG-IP management interface to only authorized administrators using firewall rules or management network segmentation, reducing the attack surface by limiting who can reach the TMUI. Additionally, monitor audit logs for unexpected administrative account creation activity (F5 Advisory, GitHub Advisory).
The vulnerability was noted by the VulDB community on Mastodon/infosec.exchange shortly after disclosure. Tenable published a detection plugin (Nessus plugin 342417) for the vulnerability within days of disclosure, indicating rapid uptake by the security scanning community. No major vendor statements beyond F5's own advisory or significant researcher commentary have been publicly identified at this time (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."