CVE-2026-66842

8.8

F5 · BIG-IP

An authenticated user can create administrative accounts via the BIG-IP Traffic Management User Interface (TMUI), leading to full system privilege escalation.

Executive summary

A critical privilege escalation vulnerability in F5 BIG-IP allows any authenticated user to create administrative accounts, potentially resulting in full system compromise.

Vulnerability

This vulnerability involves an improper authorization flaw within the Traffic Management User Interface (TMUI). It allows any authenticated user, regardless of their original role, to execute requests that create new administrative accounts on the control plane.

Business impact

The ability for a standard user to escalate to administrative status poses a severe threat to organizational security. An attacker achieving this level of control can gain full command over the BIG-IP system, leading to total compromise of the management infrastructure. With a CVSS score of 8.8, this high-severity flaw necessitates immediate attention to prevent unauthorized persistence and administrative takeover.

Remediation

Immediate Action: Upgrade all affected BIG-IP and BIG-IQ instances to the patched versions specified in F5 security advisory K000162521.

Proactive Monitoring: Review system access logs for unusual user account creation events or suspicious traffic directed at the TMUI management interface.

Compensating Controls: Restrict network access to the BIG-IP management interface to trusted administrative subnets only, effectively limiting the attack surface for unauthorized users.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the direct impact on system control, administrators must prioritize the application of vendor-supplied patches. Because this vulnerability targets the control plane, it is imperative to ensure that management interfaces are not exposed to untrusted networks while the remediation process is underway.

More F5 CVEs

Sources

Originally found and disclosed by F5 acknowledges Dan Stefan Alexandru of Pentest-Tools for bringing this issue to our attention and following the highest, per the CVE Program record.