CVE-2026-40462
published 2026-05-13CVE-2026-40462: Incorrect permission assignment vulnerabilities exist in iControl REST and TMOS shell (tmsh) undisclosed command which may allow an authenticated attacker to…
PriorityP336medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.25%
16.2th percentile
Incorrect permission assignment vulnerabilities exist in iControl REST and TMOS shell (tmsh) undisclosed command which may allow an authenticated attacker to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
89 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip | >= 16.1.0 < * | * |
| f5 | big-ip | >= 17.1.0 < 17.1.3.1 | 17.1.3.1 |
| f5 | big-ip | >= 17.5.0 < 17.5.1.4 | 17.5.1.4 |
| f5 | big-ip | >= 21.0.0 < 21.0.0.1 | 21.0.0.1 |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | 16.1.0 – 16.1.6 | — |
| f5 | big-ip_access_policy_manager | 17.1.0 – 17.1.3 | — |
| f5 | big-ip_access_policy_manager | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | 16.1.0 – 16.1.6 | — |
| f5 | big-ip_advanced_firewall_manager | 17.1.0 – 17.1.3 | — |
| f5 | big-ip_advanced_firewall_manager | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_advanced_web_application_firewall | — | — |
| f5 | big-ip_advanced_web_application_firewall | 16.1.0 – 16.1.6 | — |
| f5 | big-ip_advanced_web_application_firewall | 17.1.0 – 17.1.3 | — |
| f5 | big-ip_advanced_web_application_firewall | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 16.1.0 – 16.1.6 | — |
| f5 | big-ip_analytics | 17.1.0 – 17.1.3 | — |
| f5 | big-ip_analytics | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_application_acceleration_manager | — | — |
| f5 | big-ip_application_acceleration_manager | 16.1.0 – 16.1.6 | — |
| f5 | big-ip_application_acceleration_manager | 17.1.0 – 17.1.3 | — |
| f5 | big-ip_application_acceleration_manager | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_application_security_manager | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv4.07.1HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m5rw-fq84-2jg3: Incorrect permission assignment vulnerabilities exist in iControl REST and TMOS shell (tmsh) undisclosed command which may allow an authenticated atta
ghsa_unreviewed·2026-05-13
CVE-2026-40462 [HIGH] CWE-732 GHSA-m5rw-fq84-2jg3: Incorrect permission assignment vulnerabilities exist in iControl REST and TMOS shell (tmsh) undisclosed command which may allow an authenticated atta
Incorrect permission assignment vulnerabilities exist in iControl REST and TMOS shell (tmsh) undisclosed command which may allow an authenticated attacker to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
F5
CVE-2026-40462: Incorrect permission assignment vulnerabilities exist in iControl REST and TMOS shell (tmsh) undisclosed command whic...
vendor_f5·2026-05-13·CVSS 7.1
CVE-2026-40462 [HIGH] CWE-732 CVE-2026-40462: Incorrect permission assignment vulnerabilities exist in iControl REST and TMOS shell (tmsh) undisclosed command whic...
CVE-2026-40462: Incorrect permission assignment vulnerabilities exist in iControl REST and TMOS shell (tmsh) undisclosed command whic...
Incorrect permission assignment vulnerabilities exist in iControl REST and TMOS shell (tmsh) undisclosed command which may allow an authenticated attacker to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products: iControl REST
F5 Advisory Articles: K000156581
F5 References: https://my.f5.com/manage/s/article/K000156581
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-13
Published