CVE-2024-26026: BIG-IP Central Manager SQL Injection
An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 20.2.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26026?
CVE-2024-26026 is classified as an SQL injection vulnerability, which can lead to unauthorized access to the database.
How do I fix CVE-2024-26026?
To fix CVE-2024-26026, upgrade your F5 BIG-IP Next Central Manager software to version 20.2.0 or later.
What software versions are affected by CVE-2024-26026?
CVE-2024-26026 affects F5 BIG-IP Next Central Manager versions from 20.0.1 to 20.1.0, including all prior versions.
Is CVE-2024-26026 applicable to End of Technical Support (EoTS) versions?
CVE-2024-26026 does not apply to software versions that have reached End of Technical Support (EoTS).
What potential risks does CVE-2024-26026 pose?
CVE-2024-26026 poses risks such as unauthorized data access and possible device takeover due to SQL injection.