← Back to CVE List
CVE-2026-94127NVD
Vulnerability Summary
When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).
Impact:
This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Impact:
This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS v4.0 Base Metrics — Score 9.3 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)High
Integrity (Vulnerable System)High
Availability (Vulnerable System)High
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 9.8 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- F5 BIG-IP >= 21.1.0 and < Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
- F5 BIG-IP >= 17.5.0 and < Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
- F5 BIG-IP >= 17.1.0 and < Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
- F5 BIG-IP Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
- F5 BIG-IP Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
- F5 BIG-IP Hotfix-BIGIP-17.1.3.5.0.41.14-ENG