CVE-2026-94127: BIG-IP APM OAuth vulnerability
F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.
Other sources
When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability.
Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
— NVD
When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).
Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Discontinue use of the F5 BIG-IP APM product if mitigations are unavailable.
Event History
Frequently Asked Questions
Which deployments are exposed?
A virtual server is affected when it has both a BIG-IP APM access policy and an OAuth profile configured. BIG-IP systems running in Appliance mode are also vulnerable.
Does exploitation require credentials or user interaction?
No. An unauthenticated attacker can exploit the issue using specific malicious traffic, with no privileges or user interaction indicated.
Is the management or control plane exposed?
No. This is a data plane issue, and the provided information states that there is no control plane exposure.
What does the assessment say about versions that have reached End of Technical Support?
Versions that have reached End of Technical Support were not evaluated. Their exposure status cannot be determined from the provided assessment.