CVE-2026-28758: BIG-IP iControl REST vulnerability
When BIG-IP DNS is provisioned, a vulnerability exists in the gtmadd and bigipadd iControl REST commands that return the ssh-password parameter in cleartext in the iControl REST response and is also logged in the audit log. This may allow a highly privileged, authenticated attacker with access to the audit log to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
If BIG-IP DNS is provisioned, restrict/limit authenticated access to audit log access and iControl REST endpoints (e.g., to only trusted admin users/IPs) to prevent a highly privileged authenticated attacker from accessing the cleartext ssh-password returned by the gtm_add and bigip_add iControl REST commands and recorded in the audit log.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28758?
CVE-2026-28758 is rated as high severity due to the exposure of sensitive information.
How do I fix CVE-2026-28758?
To mitigate CVE-2026-28758, ensure that logging of sensitive information is disabled and apply any available patches from F5 Networks.
What systems are affected by CVE-2026-28758?
CVE-2026-28758 affects the F5 Networks BIG-IP systems when BIG-IP DNS is provisioned.
What are the potential impacts of CVE-2026-28758?
The potential impact of CVE-2026-28758 includes unauthorized access to sensitive SSH credentials and possible compromise of the system.
Is CVE-2026-28758 publicly disclosed?
Yes, CVE-2026-28758 has been publicly disclosed and documented in cybersecurity databases.