<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:f5:big_ip:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3af5big_ip/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 02 Sep 2026 17:15:24 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3af5big_ip/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Privilege Escalation in F5 BIG-IP TMUI via CVE-2026-66842</title><link>https://feed.craftedsignal.io/briefs/2026-09-f5-bigip-tmui-privesc/</link><pubDate>Wed, 02 Sep 2026 17:15:24 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-f5-bigip-tmui-privesc/</guid><description>An authenticated user with any role can exploit a vulnerability in the F5 BIG-IP Traffic Management User Interface to create arbitrary administrative accounts.</description><content:encoded><![CDATA[<p>CVE-2026-66842 identifies a security flaw within the F5 BIG-IP Traffic Management User Interface (TMUI). This vulnerability allows an attacker who already possesses an authenticated account on the system, regardless of their assigned role, to create new administrative accounts. The exploitation of this flaw is limited to the device's control plane; there is no identified exposure through the data plane. The primary requirement for exploitation is network access to the management interface of the BIG-IP system. This allows low-privilege users to effectively escalate their permissions to full administrative control, posing a significant risk to the integrity and confidentiality of the network infrastructure. F5 has noted that versions of BIG-IP that have reached their End of Technical Support (EoTS) have not been evaluated for this vulnerability.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability enables an attacker to gain full administrative access to the BIG-IP appliance. This grants the attacker complete control over network traffic management, policy enforcement, and configuration settings. Given the central role F5 BIG-IP devices play in enterprise networks, such unauthorized escalation could lead to widespread disruption, interception of traffic, or the exfiltration of sensitive data protected by these devices.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Restrict network access to the BIG-IP management interface to only trusted internal IP addresses or jump servers.</li>
<li>Audit existing administrative accounts for unauthorized additions created recently.</li>
<li>Monitor logs for unusual account creation activity within the TMUI management interface.</li>
<li>Review official F5 security bulletins for patches corresponding to CVE-2026-66842 and apply them to all supported versions of BIG-IP.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>privilege-escalation</category><category>network-security</category><category>f5</category></item></channel></rss>