CVE-2026-34176
published 2026-05-13CVE-2026-34176: When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit…
PriorityP354high8.7CVSS 3.1
AVNACLPRHUINSCCHIHAN
EPSS
0.69%
48.7th percentile
When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
89 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip | >= 16.1.0 < * | * |
| f5 | big-ip | >= 17.1.0 < 17.1.3.2 | 17.1.3.2 |
| f5 | big-ip | >= 17.5.0 < 17.5.1.6 | 17.5.1.6 |
| f5 | big-ip | >= 21.0.0 < 21.0.0.2 | 21.0.0.2 |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | 16.1.0 – 16.1.6 | — |
| f5 | big-ip_access_policy_manager | 17.1.0 – 17.1.3 | — |
| f5 | big-ip_access_policy_manager | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | 16.1.0 – 16.1.6 | — |
| f5 | big-ip_advanced_firewall_manager | 17.1.0 – 17.1.3 | — |
| f5 | big-ip_advanced_firewall_manager | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_advanced_web_application_firewall | — | — |
| f5 | big-ip_advanced_web_application_firewall | 16.1.0 – 16.1.6 | — |
| f5 | big-ip_advanced_web_application_firewall | 17.1.0 – 17.1.3 | — |
| f5 | big-ip_advanced_web_application_firewall | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 16.1.0 – 16.1.6 | — |
| f5 | big-ip_analytics | 17.1.0 – 17.1.3 | — |
| f5 | big-ip_analytics | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_application_acceleration_manager | — | — |
| f5 | big-ip_application_acceleration_manager | 16.1.0 – 16.1.6 | — |
| f5 | big-ip_application_acceleration_manager | 17.1.0 – 17.1.3 | — |
| f5 | big-ip_application_acceleration_manager | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_application_security_manager | — | — |
CVSS provenance
nvdv3.18.7HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
nvdv4.08.5HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
F5 BIG-IP prior 17.1.3.2/17.5.1.6/21.0.0.2 iControl REST Endpoint os command injection (K000160857 / Nessus ID 316103)
vuldb·2026-05-24·CVSS 8.5
CVE-2026-34176 [HIGH] F5 BIG-IP prior 17.1.3.2/17.5.1.6/21.0.0.2 iControl REST Endpoint os command injection (K000160857 / Nessus ID 316103)
A vulnerability, which was classified as critical, was found in F5 BIG-IP. This issue affects some unknown processing of the component iControl REST Endpoint. Such manipulation leads to os command injection.
This vulnerability is traded as CVE-2026-34176. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
GHSA
GHSA-9vx8-mp8v-r465: When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint
ghsa_unreviewed·2026-05-13
CVE-2026-34176 [HIGH] CWE-78 GHSA-9vx8-mp8v-r465: When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint
When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
F5
CVE-2026-34176: When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iCon...
vendor_f5·2026-05-13·CVSS 8.5
CVE-2026-34176 [HIGH] CWE-78 CVE-2026-34176: When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iCon...
CVE-2026-34176: When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iCon...
When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products: iControl REST
F5 Advisory Articles: K000160857
F5 References: https://my.f5.com/manage/s/article/K000160857
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-13
Published