Command injection in BIG-IP - CVE-2026-41953

 

Command injection in BIG-IP - CVE-2026-41953

Published: May 14, 2026


Vulnerability identifier: #VU131410
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-41953
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges or bypass Appliance mode restrictions.

The vulnerability exists due to command injection in TMOS when modifying configuration objects through the management port or self IP addresses. A remote privileged user can modify configuration objects to escalate privileges or bypass Appliance mode restrictions.

In Appliance mode deployments, successful exploitation can cross a security boundary. There is no data plane exposure; this is a control plane issue only.


Affected software

BIG-IP

How to mitigate CVE-2026-41953

Install security update from vendor's website.

BIG-IP - addressed in versions 17.1.3.2, 17.5.1.6, 21.0.0.2

External References

Related Security Bulletins