An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG-IQ system.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References
| Link | Resource |
|---|---|
| https://my.f5.com/manage/s/article/K000158029 | Mitigation Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-05-13 16:16
Updated : 2026-06-29 18:01
NVD link : CVE-2026-20916
Mitre link : CVE-2026-20916
CVE.ORG link : CVE-2026-20916
JSON object : View
Products Affected
f5
- big-iq_centralized_management
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
