← Back to CVE List
Vulnerability Intelligence Report
BIG-IP and BIG-IQ Configuration utility vulnerability

CVE-2026-66842

BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI). Impact: This vulnerability may allow an authenticated attacker with network access to the BIG-IP management interface to escalate privileges by creating administrative accounts on the BIG-IP system. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

No Active Exploit Signals
CVSS Base Score
8.8
HIGH
Exploitability:2.9
Impact Score:5.9
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-918 ↗CWE-918 Server-Side Request Forgery (SSRF)

Affected Products & Versions

Vendor Product Affected Versions
F5 BIG-IP 21.1.0 < 21.1.0.1 (affected), 21.0.0 < 21.0.0.3 (affected), 17.5.0 < 17.5.1.8 (affected), 17.1.0 < 17.1.3.4 (affected)
F5 BIG-IQ 8.4.0 < 8.4.2.1 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityF5, Inc. · Vendor · USA
Reserved2026-07-29T19:42:42
Published2026-09-02T15:40:53
Patch Date2026-08-19
Last Updated2026-09-03T03:56:29

LINK COPIED TO CLIPBOARD