CVE-2026-42924
published 2026-05-13CVE-2026-42924: An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP resulting in…
PriorityP352high8.7CVSS 3.1
AVNACLPRHUINSCCHIHAN
EPSS
0.25%
16.2th percentile
An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip | >= 16.1.0 < * | * |
| f5 | big-ip | >= 17.1.0 < 17.1.3.1 | 17.1.3.1 |
| f5 | big-ip | >= 17.5.0 < 17.5.1.4 | 17.5.1.4 |
| f5 | big-ip | >= 21.0.0 < 21.0.0.1 | 21.0.0.1 |
| f5 | icontrol_soap | — | — |
CVSS provenance
nvdv3.18.7HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
nvdv4.08.5HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
F5 BIG-IP prior 17.1.3.1/17.5.1.4/21.0.0.1 SNMP Configuration os command injection (K000160926 / Nessus ID 316118)
vuldb·2026-06-21·CVSS 8.7
CVE-2026-42924 [HIGH] F5 BIG-IP prior 17.1.3.1/17.5.1.4/21.0.0.1 SNMP Configuration os command injection (K000160926 / Nessus ID 316118)
A vulnerability marked as critical has been reported in F5 BIG-IP. This affects an unknown function of the component SNMP Configuration Handler. Performing a manipulation results in os command injection.
This vulnerability is identified as CVE-2026-42924. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
GHSA
GHSA-j4g2-pcp5-j4pp: An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP resulting
ghsa_unreviewed·2026-05-13
CVE-2026-42924 [HIGH] CWE-78 GHSA-j4g2-pcp5-j4pp: An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP resulting
An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
F5
CVE-2026-42924: An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects...
vendor_f5·2026-05-13·CVSS 8.5
CVE-2026-42924 [HIGH] CWE-78 CVE-2026-42924: An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects...
CVE-2026-42924: An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects...
An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products: iControl SOAP
F5 Advisory Articles: K000160926
F5 References: https://my.f5.com/manage/s/article/K000160926
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-13
Published