CVE-2026-66842
EUVD-2026-7013602.09.2026, 16:17
BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI). Impact: This vulnerability may allow an authenticated attacker with network access to the BIG-IP management interface to escalate privileges by creating administrative accounts on the BIG-IP system. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| f5 | big-ip | 21.1.0 ≤ 𝑥 < 21.1.0.1 | CNA |
| f5 | big-ip | 21.0.0 ≤ 𝑥 < 21.0.0.3 | CNA |
| f5 | big-ip | 17.5.0 ≤ 𝑥 < 17.5.1.8 | CNA |
| f5 | big-ip | 17.1.0 ≤ 𝑥 < 17.1.3.4 | CNA |
| f5 | big-ip | 8.4.0 ≤ 𝑥 < 8.4.2.1 | CNA |