Spoofing Vulnerability in BIG-IP Configuration Utility by F5 Networks
CVE-2026-20732
2.3LOW
What is CVE-2026-20732?
A security issue has been identified in the BIG-IP Configuration utility of F5 Networks that could grant an attacker the ability to spoof error messages. This vulnerability exposes systems to potential misinformation and deceives users, as incorrect error messages might mislead them regarding the state of the application. It is critical for organizations using affected versions of BIG-IP to review their configurations and ensure they are not operating on versions that have reached End of Technical Support (EoTS), as such versions may not be evaluated for this vulnerability.
Affected Version(s)
BIG-IP 17.5.0 < 17.5.1.4
BIG-IP 17.1.0 < 17.1.3.1
BIG-IP 16.1.0
References
CVSS V4
Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
F5 acknowledges Michał Majchrowicz, Marcin Wyczechowski, and Zbigniew Piotrak (members of the AFINE Team) for bringing this issue to our attention and following the highest standards of coordinated disclosure.