Cross-site request forgery in BIG-IP - CVE-2026-40703
Published: May 14, 2026
BIG-IP
Detailed vulnerability description
The vulnerability allows a remote attacker to perform unauthorized create, modify, and delete actions on the dashboard.
The vulnerability exists due to cross-site request forgery in the configuration utility dashboard when handling crafted requests from an authenticated user's browser. A remote attacker can cause an authenticated user to send a crafted request to perform unauthorized create, modify, and delete actions on the dashboard.
This is a control plane issue; there is no data plane exposure.