CVE-2024-26026: BIG-IP Central Manager SQL Injection
Published May 8, 2024
·Updated
An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI).
Affected Software
2 affected componentsFixes available
F5 BIG-IP Next Central Manager>=20.0.1<=20.1.0
20.2.0
F5 BIG-IP Next Central Manager>=20.0.1<20.2.0
Event History
May 8, 2024
Advisory Published
via F5·12:51 PM
Data Sourced
via F5·12:51 PM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·03:01 PM
Data Sourced
via MITRE·03:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
News Published
via BleepingComputer·07:52 PM
News Published
via BleepingComputer·07:53 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-26026?
CVE-2024-26026 is classified as an SQL injection vulnerability, which can lead to unauthorized access to the database.
2
How do I fix CVE-2024-26026?
To fix CVE-2024-26026, upgrade your F5 BIG-IP Next Central Manager software to version 20.2.0 or later.
3
What software versions are affected by CVE-2024-26026?
CVE-2024-26026 affects F5 BIG-IP Next Central Manager versions from 20.0.1 to 20.1.0, including all prior versions.
4
Is CVE-2024-26026 applicable to End of Technical Support (EoTS) versions?
CVE-2024-26026 does not apply to software versions that have reached End of Technical Support (EoTS).
5
What potential risks does CVE-2024-26026 pose?
CVE-2024-26026 poses risks such as unauthorized data access and possible device takeover due to SQL injection.