CVE-2026-42930
published 2026-05-13CVE-2026-42930: When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BIG-IP…
PriorityP350high8.7CVSS 3.1
AVNACLPRHUINSCCHIHAN
EPSS
0.48%
38.6th percentile
When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BIG-IP system.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip | — | — |
| f5 | big-ip | >= 16.1.0 < * | * |
| f5 | big-ip | >= 17.1.0 < 17.1.3.2 | 17.1.3.2 |
| f5 | big-ip | >= 17.5.0 < 17.5.1.6 | 17.5.1.6 |
| f5 | big-ip | >= 21.0.0 < 21.0.0.2 | 21.0.0.2 |
CVSS provenance
nvdv3.18.7HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
nvdv4.08.5HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-37mq-hr48-xhmc: When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BIG
ghsa_unreviewed·2026-05-13
CVE-2026-42930 [HIGH] CWE-35 GHSA-37mq-hr48-xhmc: When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BIG
When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BIG-IP system.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
VulDB
F5 BIG-IP prior 17.1.3.2/17.5.1.6/21.0.0.2 Appliance Mode path traversal (K000160876)
vuldb·2026-05-13·CVSS 8.5
CVE-2026-42930 [HIGH] F5 BIG-IP prior 17.1.3.2/17.5.1.6/21.0.0.2 Appliance Mode path traversal (K000160876)
A vulnerability has been found in F5 BIG-IP and classified as problematic. The affected element is an unknown function of the component Appliance Mode. The manipulation leads to path traversal: '.../...//'.
This vulnerability is documented as CVE-2026-42930. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
F5
CVE-2026-42930: When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass App...
vendor_f5·2026-05-13·CVSS 8.5
CVE-2026-42930 [HIGH] CWE-35 CVE-2026-42930: When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass App...
CVE-2026-42930: When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass App...
When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BIG-IP system.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products: BIG-IP
F5 Advisory Articles: K000160876
F5 References: https://my.f5.com/manage/s/article/K000160876
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-13
Published