Privilege Escalation Vulnerability in BIG-IP Management Interface by F5 Networks
CVE-2026-66842

8.7HIGH

Key Information:

Vendor

F5

Vendor
CVE Published:
2 September 2026

What is CVE-2026-66842?

F5 Networks' BIG-IP presents a vulnerability that permits authenticated users, regardless of their assigned roles, to unintentionally create administrative accounts through undisclosed requests to the Traffic Management User Interface (TMUI). This issue, fundamentally a control plane concern, may allow an attacker with network access to the management interface to escalate their privileges. Users should ensure they are operating supported versions of the software to mitigate this risk.

Affected Version(s)

BIG-IP 21.1.0 < 21.1.0.1

BIG-IP 21.0.0 < 21.0.0.3

BIG-IP 17.5.0 < 17.5.1.8

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

F5 acknowledges Dan Stefan Alexandru of Pentest-Tools for bringing this issue to our attention and following the highest standards of coordinated disclosure.
.