Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References
| Link | Resource |
|---|---|
| https://my.f5.com/manage/s/article/K32950402 | Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
No history.
Information
Published : 2026-05-13 16:16
Updated : 2026-06-24 14:52
NVD link : CVE-2026-41954
Mitre link : CVE-2026-41954
CVE.ORG link : CVE-2026-41954
JSON object : View
Products Affected
f5
- big-ip_automation_toolchain
- big-ip_carrier-grade_nat
- big-ip_global_traffic_manager
- big-ip_edge_gateway
- big-ip_application_acceleration_manager
- big-ip_access_policy_manager
- big-ip_application_security_manager
- big-ip_fraud_protection_service
- big-ip_container_ingress_services
- big-ip_policy_enforcement_manager
- big-ip_webaccelerator
- big-ip_websafe
- big-ip_analytics
- big-ip_local_traffic_manager
- big-ip_ssl_orchestrator
- big-ip_advanced_firewall_manager
- big-ip_application_visibility_and_reporting
- big-ip_ddos_hybrid_defender
- big-ip_domain_name_system
- big-ip_link_controller
- big-ip_advanced_web_application_firewall
- big-iq_centralized_management
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
