SB2026051441 - IP-based access restrictions bypass in BIG-IP httpd



SB2026051441 - IP-based access restrictions bypass in BIG-IP httpd

Published: May 14, 2026

Security Bulletin ID SB2026051441
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Unprotected Alternate Channel (CVE-ID: CVE-2026-40435)

The vulnerability allows a remote attacker to connect to the BIG-IP control plane HTTP services from blocked addresses.

The vulnerability exists due to unprotected alternate channel in httpd access control when handling requests to endpoints not covered by configured IP-based access restrictions. A remote attacker can send requests to exposed endpoints to connect to the BIG-IP control plane HTTP services from blocked addresses.

Valid login credentials are still required to interact with the BIG-IP system, and there is no data plane exposure.


Remediation

Install update from vendor's website.