Privilege Escalation in F5 BIG-IP TMUI via CVE-2026-66842
An authenticated user with any role can exploit a vulnerability in the F5 BIG-IP Traffic Management User Interface to create arbitrary administrative accounts.
CVE search metadata
CVE search record: CVE-2026-66842. Severity: high. CVSS: 8.8. KEV: no. Product: BIG-IP. Brief: Privilege Escalation in F5 BIG-IP TMUI via CVE-2026-66842. Brief link: https://feed.craftedsignal.io/briefs/2026-09-f5-bigip-tmui-privesc/
CVE-2026-66842 identifies a security flaw within the F5 BIG-IP Traffic Management User Interface (TMUI). This vulnerability allows an attacker who already possesses an authenticated account on the system, regardless of their assigned role, to create new administrative accounts. The exploitation of this flaw is limited to the device's control plane; there is no identified exposure through the data plane. The primary requirement for exploitation is network access to the management interface of the BIG-IP system. This allows low-privilege users to effectively escalate their permissions to full administrative control, posing a significant risk to the integrity and confidentiality of the network infrastructure. F5 has noted that versions of BIG-IP that have reached their End of Technical Support (EoTS) have not been evaluated for this vulnerability.
Impact
Successful exploitation of this vulnerability enables an attacker to gain full administrative access to the BIG-IP appliance. This grants the attacker complete control over network traffic management, policy enforcement, and configuration settings. Given the central role F5 BIG-IP devices play in enterprise networks, such unauthorized escalation could lead to widespread disruption, interception of traffic, or the exfiltration of sensitive data protected by these devices.
Recommendation
- Restrict network access to the BIG-IP management interface to only trusted internal IP addresses or jump servers.
- Audit existing administrative accounts for unauthorized additions created recently.
- Monitor logs for unusual account creation activity within the TMUI management interface.
- Review official F5 security bulletins for patches corresponding to CVE-2026-66842 and apply them to all supported versions of BIG-IP.
Immediate actions
Review TMUI access logs for unauthorized account creation attempts
Mitigations
Apply patches provided by F5 for CVE-2026-66842
CVE-2026-66842