CVE-2026-40061: iControl REST and tmsh vulnerability
When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In Appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40061?
The severity of CVE-2026-40061 is rated as high, with a CVSS score of 8.5.
How do I fix CVE-2026-40061?
To fix CVE-2026-40061, ensure you apply the latest security patches provided by F5 Networks for BIG-IP DNS.
Who is affected by CVE-2026-40061?
CVE-2026-40061 affects users of F5 BIG-IP DNS who have an authenticated user role of Resource Administrator or Administrator.
What type of vulnerability is CVE-2026-40061?
CVE-2026-40061 is identified as a command injection vulnerability.
What can an attacker do with CVE-2026-40061?
An authenticated attacker can execute arbitrary system commands with higher privileges due to CVE-2026-40061.