An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG-IQ system.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
References
| Link | Resource |
|---|---|
| https://my.f5.com/manage/s/article/K000158029 | Mitigation Vendor Advisory |
Configurations
History
29 Jun 2026, 18:01
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://my.f5.com/manage/s/article/K000158029 - Mitigation, Vendor Advisory | |
| CPE | cpe:2.3:a:f5:big-iq_centralized_management:8.4.0:*:*:*:*:*:*:* | |
| First Time |
F5
F5 big-iq Centralized Management |
13 May 2026, 16:27
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-13 16:16
Updated : 2026-06-29 18:01
NVD link : CVE-2026-20916
Mitre link : CVE-2026-20916
CVE.ORG link : CVE-2026-20916
JSON object : View
Products Affected
f5
- big-iq_centralized_management
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
