Impact
In F5 BIG‑IP and BIG‑IQ, any authenticated user can create new administrative accounts through the Traffic Management User Interface (TMUI). The flaw allows an attacker with any role—valid or compromised—to add an account that bypasses existing role restrictions and grants full administrative control over the device. This is a control plane privilege escalation and does not expose the data plane.
Affected Systems
The vulnerability affects F5 BIG‑IP and BIG‑IQ platforms; the advisory does not specify exact firmware or software release numbers, and versions that have reached End of Technical Support are not evaluated.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, while the EPSS score is not available so the likelihood of exploitation remains uncertain. The flaw is not listed in CISA KEV. Exploitation requires an authenticated session to the TMUI over the network, which can be established by any user with valid credentials. If an attacker compromises or obtains legitimate credentials, they can create an administrative account and elevate privileges to full control of the device.
OpenCVE Enrichment