Description
BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI).




Impact:

This vulnerability may allow an authenticated attacker with network access to the BIG-IP management interface to escalate privileges by creating administrative accounts on the BIG-IP system. There is no data plane exposure; this is a control plane issue only.




Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published: 2026-09-02
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In F5 BIG‑IP and BIG‑IQ, any authenticated user can create new administrative accounts through the Traffic Management User Interface (TMUI). The flaw allows an attacker with any role—valid or compromised—to add an account that bypasses existing role restrictions and grants full administrative control over the device. This is a control plane privilege escalation and does not expose the data plane.

Affected Systems

The vulnerability affects F5 BIG‑IP and BIG‑IQ platforms; the advisory does not specify exact firmware or software release numbers, and versions that have reached End of Technical Support are not evaluated.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, while the EPSS score is not available so the likelihood of exploitation remains uncertain. The flaw is not listed in CISA KEV. Exploitation requires an authenticated session to the TMUI over the network, which can be established by any user with valid credentials. If an attacker compromises or obtains legitimate credentials, they can create an administrative account and elevate privileges to full control of the device.

Generated by OpenCVE AI on September 3, 2026 at 10:10 UTC.

Remediation

Vendor Workaround

None


OpenCVE Recommended Actions

  • Apply any currently available F5 patches or upgrade to a firmware version that fixes the TMUI privilege escalation flaw.
  • Restrict network access to the Traffic Management User Interface so that only trusted management hosts can reach it, reducing the attack surface for authenticated exploitation.
  • Enforce strict role‑based permissions by allowing only explicitly designated administrative users the rights to create new administrative accounts and regularly audit existing account privileges.

Generated by OpenCVE AI on September 3, 2026 at 10:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared F5
F5 big-ip
F5 big-iq
Vendors & Products F5
F5 big-ip
F5 big-iq

Wed, 02 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI). Impact: This vulnerability may allow an authenticated attacker with network access to the BIG-IP management interface to escalate privileges by creating administrative accounts on the BIG-IP system. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Title BIG-IP and BIG-IQ Configuration utility vulnerability
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: f5

Published:

Updated: 2026-09-03T03:56:29.619Z

Reserved: 2026-07-29T19:42:42.204Z

Link: CVE-2026-66842

cve-icon Vulnrichment

Updated: 2026-09-02T17:56:22.530Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-02T16:17:18.910

Modified: 2026-09-03T13:06:01.337

Link: CVE-2026-66842

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T10:15:05Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)