CVE-2024-26026

Severity
7.5HIGH
EPSS
89.4%
top 0.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 8
Latest updateSep 25

Description

An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5f5/big-ip_next_central_manager20.0.120.2.0
NVDf5/big-ip_next_central_manager20.0.120.2.0

🔴Vulnerability Details

2
GHSA
GHSA-fj43-9cjj-qw2v: An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI)2024-05-08
CVEList
BIG-IP Central Manager SQL Injection2024-05-08

🔍Detection Rules

1
Suricata
ET WEB_SPECIFIC_APPS F5 BIG-IP Next Central Manager SQL Injection (CVE-2024-26026)2024-09-25

📋Vendor Advisories

1
F5
CVE-2024-26026: An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI)2024-05-08

🕵️Threat Intelligence

1
Bleepingcomputer
New BIG-IP Next Central Manager bugs allow device takeover2024-05-08
CVE-2024-26026 (HIGH CVSS 7.5) | An SQL injection vulnerability exis | cvebase.io