CVE-2026-42406
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.5
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.15%
- CWE
- CWE-267
- Published
- 2026-05-13
- Last modified
- 2026-05-14
Affected products
- F5 BIG-IP
- F5 BIG-IP
- F5 BIG-IP
- F5 BIG-IP
- F5 BIG-IP
- F5 BIG-IQ
Weakness type
Related vulnerabilities
- CVE-2026-18858 — IBM i is Affected By Obtaining Sensitive Information Vulnerability in OpenSSH []
- CVE-2026-81161 — Content Moderation Notifications - Moderately critical - Access bypass - SA-CONTRIB-2026-107
- CVE-2025-36255 — DS8900F and DS8A00 Privilege Escalation
- CVE-2026-10090 — Multicluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped clusterrolebinding and become cluster-admin via application subscription
- CVE-2026-6816 — TFA Basic Plugins - Access Bypass
- CVE-2026-9560 — Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows...
- CVE-2026-27314 — Apache Cassandra: Privilege escalation via ADD IDENTITY authorization bypass
- CVE-2026-2460 — A vulnerability exists in REB500 for an authenticated user with low-level privileges to access and...