CVE-2026-41217: BIG-IP tmsh vulnerability
A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with resource administrator or administrator role to execute arbitrary system commands with higher privileges. In Appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Audit all BIG-IP user accounts and revoke the 'resource administrator' and 'administrator' roles from any accounts that do not require those privileges; restrict these roles to a minimal set of trusted administrators.
BIG-IP (tmsh) user role assignments role assignment = remove 'resource administrator' and 'administrator' roles from accounts that do not require them - Compensating control
For Appliance mode deployments, restrict access to management interfaces (tmsh/management network) by applying firewall/ACL rules to allow only trusted management IPs, place appliances on isolated management VLANs, and limit remote access to trusted administrative hosts.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41217?
CVE-2026-41217 has a high severity score of 8.3.
How do I fix CVE-2026-41217?
To mitigate CVE-2026-41217, upgrade to the latest patched version of F5 BIG-IP software.
Who can exploit CVE-2026-41217?
An authenticated attacker with resource administrator or administrator role can exploit CVE-2026-41217.
What could an attacker achieve by exploiting CVE-2026-41217?
Exploitation of CVE-2026-41217 may allow an attacker to execute arbitrary system commands with higher privileges.
Which F5 BIG-IP products are affected by CVE-2026-41217?
CVE-2026-41217 affects multiple F5 BIG-IP products including Access Policy Manager, Advanced Firewall Manager, and Application Security Manager.