← Back to search

CVE-2026-94127

9.8 CRITICAL

Published 2026-09-22 · Updated 2026-09-23

AI risk analysis

Summary
This vulnerability allows unauthenticated attackers to perform remote code execution when a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, leading to potential system compromise.
Exploitability
Exploitation is relatively straightforward given the specific configuration requirements, and an attacker must be able to send specific malicious traffic.
Blast radius
If exploited, this vulnerability could result in complete system compromise, including data theft and control of the BIG-IP system.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable BIG-IP APM when not used as an OAuth Authorization Server, or upgrade to the latest supported version of BIG-IP APM.
rceunauthwebbig-ipapm

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-122

Vendors

f5

Products

big-ip access policy manager

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.