CVE-2026-41225
A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Scoring
- Severity
- HIGH
- CVSS base score
- 9.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.27%
- CWE
- CWE-648
- Published
- 2026-05-13
- Last modified
- 2026-05-14
Affected products
- F5 BIG-IP
- F5 BIG-IP
- F5 BIG-IP
- F5 BIG-IP
- F5 BIG-IP
Weakness type
Related vulnerabilities
- CVE-2026-63727 — Anchore Enterprise Privilege Escalation via User Management API
- CVE-2026-54424 — An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a...
- CVE-2026-11877 — Missing Authorization Vulnerability in OpenText Access Manager
- CVE-2026-9560 — Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows...
- CVE-2026-41386 — OpenClaw < 2026.3.22 - Privilege Escalation via Unbound Bootstrap Setup Codes
- CVE-2026-41329 — OpenClaw < 2026.3.31 - Sandbox Bypass via Heartbeat Context Inheritance and senderIsOwner Escalation
- CVE-2026-35669 — OpenClaw < 2026.3.25 - Privilege Escalation via Gateway Plugin HTTP Authentication Scope
- CVE-2026-35663 — OpenClaw < 2026.3.25 - Privilege Escalation via Backend Reconnect Scope Self-Claim