Skip to content
Threat Feed
high advisory

Privilege Escalation in F5 BIG-IP TMUI via CVE-2026-66842

An authenticated user with any role can exploit a vulnerability in the F5 BIG-IP Traffic Management User Interface to create arbitrary administrative accounts.

CVE search metadata

CVE search record: CVE-2026-66842. Severity: high. CVSS: 8.8. KEV: no. Product: BIG-IP. Brief: Privilege Escalation in F5 BIG-IP TMUI via CVE-2026-66842. Brief link: https://feed.craftedsignal.io/briefs/2026-09-f5-bigip-tmui-privesc/

CVE-2026-66842 identifies a security flaw within the F5 BIG-IP Traffic Management User Interface (TMUI). This vulnerability allows an attacker who already possesses an authenticated account on the system, regardless of their assigned role, to create new administrative accounts. The exploitation of this flaw is limited to the device's control plane; there is no identified exposure through the data plane. The primary requirement for exploitation is network access to the management interface of the BIG-IP system. This allows low-privilege users to effectively escalate their permissions to full administrative control, posing a significant risk to the integrity and confidentiality of the network infrastructure. F5 has noted that versions of BIG-IP that have reached their End of Technical Support (EoTS) have not been evaluated for this vulnerability.

Impact

Successful exploitation of this vulnerability enables an attacker to gain full administrative access to the BIG-IP appliance. This grants the attacker complete control over network traffic management, policy enforcement, and configuration settings. Given the central role F5 BIG-IP devices play in enterprise networks, such unauthorized escalation could lead to widespread disruption, interception of traffic, or the exfiltration of sensitive data protected by these devices.

Recommendation

  • Restrict network access to the BIG-IP management interface to only trusted internal IP addresses or jump servers.
  • Audit existing administrative accounts for unauthorized additions created recently.
  • Monitor logs for unusual account creation activity within the TMUI management interface.
  • Review official F5 security bulletins for patches corresponding to CVE-2026-66842 and apply them to all supported versions of BIG-IP.

Immediate actions

Review TMUI access logs for unauthorized account creation attempts

SOC 24h

Mitigations

Apply patches provided by F5 for CVE-2026-66842

immediate IT Operations

CVE-2026-66842