ZeroHour

CVE-2026-66842

large

Authenticated Privilege Escalation in F5 BIG-IP TMUI

CVSS 4.0
8.7 high
EPSS
<1%p20
Published
()
Modified
AI analysis

F5 BIG-IP contains a privilege escalation flaw in the Traffic Management User Interface (TMUI), the device's web-based management console, where an authenticated user of any role can create new administrative user accounts by sending an undisclosed request to TMUI (the advisory classifies the weakness as CWE-918). To trigger it, an attacker needs valid credentials for any account on the system plus network access to the BIG-IP management interface; this is a control plane issue only, with no exposure through the data plane. A successful attacker gains administrative accounts on the appliance, and the CVSS 4.0 base score of 8.7 (High) reflects high confidentiality, integrity, and availability impact on the vulnerable system. Any organization running supported BIG-IP software is potentially affected, though versions that have reached End of Technical Support are not evaluated and specific affected or fixed version ranges are not provided in this data. Exploitation has not been reported: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates a 0.3% probability of exploitation within 30 days (20th percentile).

What to do: Restrict access to the BIG-IP management interface to trusted administrative networks or host allow-lists (avoid internet-exposed TMUI), and audit existing local and remote user accounts for any unexpectedly created administrators. Apply the fixed BIG-IP release specified in F5's security advisory once you map it to your software train (version numbers are not included in this data), noting that EoTS versions are not evaluated and should be migrated; continue monitoring F5 SIRT and TMUI logs for account-creation activity.

Affected
F5 BIG-IP (TMUI management interface, control plane only)
Estimated exposure
largeroughly tens of thousands of BIG-IP deployments with TMUI access potentially exposed (overall install base likely in the hundreds of thousands; exploitation… — Based on historical internet-wide scans during prior BIG-IP TMUI vulnerabilities, which repeatedly found on the order of 100,000+ BIG-IP devices internet-visible with management-interface exposure in the tens of thousands, plus F5's large…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI). Impact: This vulnerability may allow an authenticated attacker with network access to the BIG-IP management interface to escalate privileges by creating administrative accounts on the BIG-IP system. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Weakness
CWE-918
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.