SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-66842

HIGH · CVSS 8.8 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

BIG-IP is vulnerable due to a flaw that allows authenticated users to create administrative accounts via the Traffic Management User Interface (TMUI). This privilege escalation could enable attackers with network access to gain elevated control over the system, posing significant security risks. Organizations using BIG-IP, especially those with active management interfaces, should prioritize addressing this vulnerability to safeguard their environments.

CVE
CVE-2026-66842
Severity
HIGH
CVSS
8.8
EPSS
0.28%
BIG-IP

Original NVD Description

BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI). Impact: This vulnerability may allow an authenticated attacker with network access to the BIG-IP management interface to escalate privileges by creating administrative accounts on the BIG-IP system. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.