Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-66842— BIG-IP and BIG-IQ Configuration utility vulnerability

Quick assessment

Affected
F5 BIG-IP
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

BIG-IP 存在一个漏洞,任何角色的经过认证的用户都可能通过向流量管理用户界面(TMUI)发送一个未公开的请求来创建管理员账户。 影响: 该漏洞可能允许一个已认证且能够访问 BIG-IP 管理接口的攻击者,通过在 BIG-IP 系统上创建管理员账户来提升权限。此漏洞仅涉及控制平面,不涉及数据平面。 备注: 已达到技术支持终止期(End of Technical Support, EoTS)的软件版本未纳入评估范围。

CVSS 8.8 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-66842

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
BIG-IP and BIG-IQ Configuration utility vulnerability
Source: CVE Program / CVE List V5
Vulnerability Description
BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI). Impact: This vulnerability may allow an authenticated attacker with network access to the BIG-IP management interface to escalate privileges by creating administrative accounts on the BIG-IP system. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
F5 BIG-IP 21.1.0 ~ 21.1.0.1 -
F5 BIG-IQ 8.4.0 ~ 8.4.2.1 -

II. Public POCs for CVE-2026-66842

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-66842

登录查看更多情报信息。

Other References for CVE-2026-66842 (1)

Same Patch Batch · F5 · 2026-09-02 · 7 CVEs total

CVE-2026-77180 8.3 HIGH NGINX Ingress Controller vulnerability
CVE-2026-18329 8.2 HIGH NGINX ngx_http_js_module vulnerability
CVE-2026-78689 8.1 HIGH NGINX ngx_http_js_module vulnerablility
CVE-2026-66362 8.1 HIGH NGF vulnerability
CVE-2026-78222 7.5 HIGH NGINX ngx_http_js_module vulnerability
CVE-2026-63020 3.1 LOW BIG-IP Configuration utility vulnerability

IV. Related Vulnerabilities

V. Comments for CVE-2026-66842

No comments yet


Leave a comment