CVE-2026-40631
published 2026-05-13CVE-2026-40631: An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in privilege…
PriorityP353high8.7CVSS 3.1
AVNACLPRHUINSCCHIHAN
EPSS
0.25%
16.2th percentile
An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
89 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip | >= 16.1.0 < * | * |
| f5 | big-ip | >= 17.1.0 < 17.1.3.2 | 17.1.3.2 |
| f5 | big-ip | >= 17.5.0 < 17.5.1.6 | 17.5.1.6 |
| f5 | big-ip | >= 21.0.0 < 21.0.0.2 | 21.0.0.2 |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | 16.1.0 – 16.1.6 | — |
| f5 | big-ip_access_policy_manager | 17.1.0 – 17.1.3 | — |
| f5 | big-ip_access_policy_manager | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | 16.1.0 – 16.1.6 | — |
| f5 | big-ip_advanced_firewall_manager | 17.1.0 – 17.1.3 | — |
| f5 | big-ip_advanced_firewall_manager | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_advanced_web_application_firewall | — | — |
| f5 | big-ip_advanced_web_application_firewall | 16.1.0 – 16.1.6 | — |
| f5 | big-ip_advanced_web_application_firewall | 17.1.0 – 17.1.3 | — |
| f5 | big-ip_advanced_web_application_firewall | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 16.1.0 – 16.1.6 | — |
| f5 | big-ip_analytics | 17.1.0 – 17.1.3 | — |
| f5 | big-ip_analytics | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_application_acceleration_manager | — | — |
| f5 | big-ip_application_acceleration_manager | 16.1.0 – 16.1.6 | — |
| f5 | big-ip_application_acceleration_manager | 17.1.0 – 17.1.3 | — |
| f5 | big-ip_application_acceleration_manager | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_application_security_manager | — | — |
CVSS provenance
nvdv3.18.7HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
nvdv4.08.5HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v83q-vrmw-32xv: An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in pr
ghsa_unreviewed·2026-05-13
CVE-2026-40631 [HIGH] CWE-552 GHSA-v83q-vrmw-32xv: An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in pr
An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
F5
CVE-2026-40631: An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects thro...
vendor_f5·2026-05-13·CVSS 8.5
CVE-2026-40631 [HIGH] CWE-552 CVE-2026-40631: An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects thro...
CVE-2026-40631: An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects thro...
An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products: iControl SOAP
F5 Advisory Articles: K000160979
F5 References: https://my.f5.com/manage/s/article/K000160979
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-13
Published