CVE-2026-66842
largeAuthenticated Privilege Escalation in F5 BIG-IP TMUI
F5 BIG-IP contains a privilege escalation flaw in the Traffic Management User Interface (TMUI), the device's web-based management console, where an authenticated user of any role can create new administrative user accounts by sending an undisclosed request to TMUI (the advisory classifies the weakness as CWE-918). To trigger it, an attacker needs valid credentials for any account on the system plus network access to the BIG-IP management interface; this is a control plane issue only, with no exposure through the data plane. A successful attacker gains administrative accounts on the appliance, and the CVSS 4.0 base score of 8.7 (High) reflects high confidentiality, integrity, and availability impact on the vulnerable system. Any organization running supported BIG-IP software is potentially affected, though versions that have reached End of Technical Support are not evaluated and specific affected or fixed version ranges are not provided in this data. Exploitation has not been reported: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates a 0.3% probability of exploitation within 30 days (20th percentile).
What to do: Restrict access to the BIG-IP management interface to trusted administrative networks or host allow-lists (avoid internet-exposed TMUI), and audit existing local and remote user accounts for any unexpectedly created administrators. Apply the fixed BIG-IP release specified in F5's security advisory once you map it to your software train (version numbers are not included in this data), noting that EoTS versions are not evaluated and should be migrated; continue monitoring F5 SIRT and TMUI logs for account-creation activity.
| F5 BIG-IP (TMUI management interface, control plane only) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI). Impact: This vulnerability may allow an authenticated attacker with network access to the BIG-IP management interface to escalate privileges by creating administrative accounts on the BIG-IP system. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- Weakness
- CWE-918
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.