Privilege Escalation Vulnerability in BIG-IP and BIG-IQ by F5 Networks
CVE-2026-40698
8.5HIGH
What is CVE-2026-40698?
A vulnerability exists in F5 Networks' BIG-IP and BIG-IQ systems, allowing an authenticated attacker with Resource Administrator privileges to create SNMP configuration objects via iControl REST or the TMOS shell (tmsh). This configuration flaw poses a significant risk of privilege escalation, enabling attackers to gain unauthorized access to resources and potentially compromise the integrity of the system. It's imperative to apply the latest patches and updates to mitigate this vulnerability and protect network security.
Affected Version(s)
BIG-IP 21.0.0 < 21.0.0.2
BIG-IP 17.5.0 < 17.5.1.6
BIG-IP 17.1.0 < 17.1.3.2