CVE-2026-40631
An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Faiblesse
An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Produits concernés
- f5 big-ip_access_policy_manager
- f5 big-ip_advanced_firewall_manager
- f5 big-ip_advanced_web_application_firewall
- f5 big-ip_analytics
- f5 big-ip_application_acceleration_manager
- f5 big-ip_application_security_manager
- f5 big-ip_application_visibility_and_reporting
- f5 big-ip_automation_toolchain
Références
Trouvez la faille avant un attaquant.
Connectez-vous avec GitHub et lancez votre premier audit en moins d'une minute. L'offre gratuite ne nécessite aucune carte bancaire.