AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-26415

HIGH · CVSS 7.7 EPSS 0.71%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-05-05 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.7. It affects F5, BIG-IP. Exploitation may require the attacker to be authenticated.

CVE
CVE-2022-26415
Severity
HIGH
CVSS
7.7
EPSS
0.71%
F5 BIG-IP

Original NVD Description

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Related CVEs

Other vulnerabilities affecting the same vendor(s)