F5 Networks BIG-IP : BIG-IP APM vulnerability (K000162605)

critical Nessus Plugin ID 350284

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

The version of F5 Networks BIG-IP installed on the remote host is prior to 17.1.3.5.0.41.14 / 17.5.1.9.0.160.12 / 21.1.0.2.0.30.22. It is, therefore, affected by a vulnerability as referenced in the K000162605 advisory.

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. (CVE-2026-94127)

Tenable has extracted the preceding description block directly from the F5 Networks BIG-IP security advisory.

Administrators should first determine whether a BIG-IP APM access policy and an OAuth profile are configured together on a virtual server, since this configuration is required for exposure.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to BIG-IP 17.1.3.5.0.41.14 / 17.5.1.9.0.160.12 / 21.1.0.2.0.30.22 or later.

See Also

https://my.f5.com/manage/s/article/K000162605

Plugin Details

Severity: Critical

ID: 350284

File Name: f5_bigip_SOL000162605.nasl

Version: 1.1

Type: Local

Published: 9/25/2026

Updated: 9/25/2026

Configuration: Enable paranoid mode

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.5

Percentile: 99.87

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-94127

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v4

Risk Factor: Critical

Base Score: 9.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

CPE: cpe:/a:f5:big-ip_access_policy_manager, cpe:/h:f5:big-ip

Required KB Items: Host/local_checks_enabled, Settings/ParanoidReport, Host/BIG-IP/hotfix, Host/BIG-IP/modules, Host/BIG-IP/version

Patch Publication Date: 9/22/2026

Vulnerability Publication Date: 9/22/2026

Reference Information

CVE: CVE-2026-94127

CWE: 122