{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3af5big_ip/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:f5:big_ip:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-66842"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["BIG-IP"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","network-security","f5"],"_cs_type":"advisory","_cs_vendors":["F5"],"content_html":"\u003cp\u003eCVE-2026-66842 identifies a security flaw within the F5 BIG-IP Traffic Management User Interface (TMUI). This vulnerability allows an attacker who already possesses an authenticated account on the system, regardless of their assigned role, to create new administrative accounts. The exploitation of this flaw is limited to the device's control plane; there is no identified exposure through the data plane. The primary requirement for exploitation is network access to the management interface of the BIG-IP system. This allows low-privilege users to effectively escalate their permissions to full administrative control, posing a significant risk to the integrity and confidentiality of the network infrastructure. F5 has noted that versions of BIG-IP that have reached their End of Technical Support (EoTS) have not been evaluated for this vulnerability.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability enables an attacker to gain full administrative access to the BIG-IP appliance. This grants the attacker complete control over network traffic management, policy enforcement, and configuration settings. Given the central role F5 BIG-IP devices play in enterprise networks, such unauthorized escalation could lead to widespread disruption, interception of traffic, or the exfiltration of sensitive data protected by these devices.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestrict network access to the BIG-IP management interface to only trusted internal IP addresses or jump servers.\u003c/li\u003e\n\u003cli\u003eAudit existing administrative accounts for unauthorized additions created recently.\u003c/li\u003e\n\u003cli\u003eMonitor logs for unusual account creation activity within the TMUI management interface.\u003c/li\u003e\n\u003cli\u003eReview official F5 security bulletins for patches corresponding to CVE-2026-66842 and apply them to all supported versions of BIG-IP.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-02T17:15:24Z","date_published":"2026-09-02T17:15:24Z","id":"https://feed.craftedsignal.io/briefs/2026-09-f5-bigip-tmui-privesc/","summary":"An authenticated user with any role can exploit a vulnerability in the F5 BIG-IP Traffic Management User Interface to create arbitrary administrative accounts.","title":"Privilege Escalation in F5 BIG-IP TMUI via CVE-2026-66842","url":"https://feed.craftedsignal.io/briefs/2026-09-f5-bigip-tmui-privesc/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:f5:big_ip:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}