CVE-2026-42780: BIG-IP SSL Orchestrator vulnerability
A directory traversal vulnerability exists in BIG-IP SSL Orchestrator that allows an authenticated attacker with high privilege to overwrite, delete or corrupt arbitrary local files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42780?
CVE-2026-42780 is considered a critical vulnerability due to its potential for high privilege exploitation that allows authenticated attackers to affect local files.
How do I fix CVE-2026-42780?
To remediate CVE-2026-42780, update to a fixed version of BIG-IP SSL Orchestrator provided by F5 Networks.
Who is affected by CVE-2026-42780?
CVE-2026-42780 affects users of F5 Networks BIG-IP SSL Orchestrator, specifically those with high privilege access.
What kind of attack does CVE-2026-42780 enable?
CVE-2026-42780 enables directory traversal attacks that allow attackers to overwrite, delete, or corrupt arbitrary local files.
Is there a workaround for CVE-2026-42780?
Currently, the best approach for CVE-2026-42780 is to upgrade to the latest patched version as no formal workaround has been provided.