Impact:
This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
An iRule is available upon request. Open a ticket with F5 support to request this.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://my.f5.com/manage/s/article/K000162605 |
|
Tue, 22 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
kev
|
Tue, 22 Sep 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
F5
F5 big-ip |
|
| Vendors & Products |
F5
F5 big-ip |
Tue, 22 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Title | BIG-IP APM OAuth vulnerability | |
| Weaknesses | CWE-122 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: f5
Published:
Updated: 2026-09-22T19:49:24.074Z
Reserved: 2026-09-20T17:39:19.975Z
Link: CVE-2026-94127
No data.
Status : Awaiting Analysis
Published: 2026-09-22T15:17:24.313
Modified: 2026-09-22T19:09:58.680
Link: CVE-2026-94127
No data.
OpenCVE Enrichment
Updated: 2026-09-22T16:15:08Z
-
CWE-122
Heap-based Buffer Overflow