CVE-2026-66842
8.8F5 · BIG-IP
An authenticated user can create administrative accounts via the BIG-IP Traffic Management User Interface (TMUI), leading to full system privilege escalation.
Executive summary
A critical privilege escalation vulnerability in F5 BIG-IP allows any authenticated user to create administrative accounts, potentially resulting in full system compromise.
Vulnerability
This vulnerability involves an improper authorization flaw within the Traffic Management User Interface (TMUI). It allows any authenticated user, regardless of their original role, to execute requests that create new administrative accounts on the control plane.
Business impact
The ability for a standard user to escalate to administrative status poses a severe threat to organizational security. An attacker achieving this level of control can gain full command over the BIG-IP system, leading to total compromise of the management infrastructure. With a CVSS score of 8.8, this high-severity flaw necessitates immediate attention to prevent unauthorized persistence and administrative takeover.
Remediation
Immediate Action: Upgrade all affected BIG-IP and BIG-IQ instances to the patched versions specified in F5 security advisory K000162521.
Proactive Monitoring: Review system access logs for unusual user account creation events or suspicious traffic directed at the TMUI management interface.
Compensating Controls: Restrict network access to the BIG-IP management interface to trusted administrative subnets only, effectively limiting the attack surface for unauthorized users.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the direct impact on system control, administrators must prioritize the application of vendor-supplied patches. Because this vulnerability targets the control plane, it is imperative to ensure that management interfaces are not exposed to untrusted networks while the remediation process is underway.
More F5 CVEs
Sources
Originally found and disclosed by F5 acknowledges Dan Stefan Alexandru of Pentest-Tools for bringing this issue to our attention and following the highest, per the CVE Program record.