CVE-2026-66842: BIG-IP and BIG-IQ Configuration utility vulnerability
BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI).
Impact:
This vulnerability may allow an authenticated attacker with network access to the BIG-IP management interface to escalate privileges by creating administrative accounts on the BIG-IP system. There is no data plane exposure; this is a control plane issue only.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
BIG-IP systems whose management interface is reachable over the network are exposed if an attacker can authenticate to TMUI with any user role. The issue affects the control plane only; there is no data plane exposure described.
What does an attacker need to exploit it?
An attacker needs network access to the BIG-IP management interface and valid credentials for an authenticated TMUI user account. No user interaction is required, and even non-administrative roles may be sufficient.
What is the likely impact of successful exploitation?
An attacker may create administrative user accounts on the BIG-IP system, allowing privilege escalation to administrative access. The reported impact includes high confidentiality, integrity, and availability impact.
Are end-of-support BIG-IP versions covered by the evaluation?
No. Software versions that have reached End of Technical Support are not evaluated.