{"id":"CVE-2026-94127","published":"2026-09-22T15:17:24.313","lastModified":"2026-09-23T14:32:07.910","description":"When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability.\n\nImpact:\nThis vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure.\n\n \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-122"],"vendors":["f5"],"products":["big-ip access policy manager"],"references":[{"url":"https://my.f5.com/manage/s/article/K000162605","tags":["Vendor Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-94127","tags":["US Government Resource"]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This vulnerability allows unauthenticated attackers to perform remote code execution when a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, leading to potential system compromise.","exploitability":"Exploitation is relatively straightforward given the specific configuration requirements, and an attacker must be able to send specific malicious traffic.","blast_radius":"If exploited, this vulnerability could result in complete system compromise, including data theft and control of the BIG-IP system.","remediation":"Disable BIG-IP APM when not used as an OAuth Authorization Server, or upgrade to the latest supported version of BIG-IP APM.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","unauth","web","big-ip","apm"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:49:43.696Z"}}