Impact:
An attacker may trick authenticated BIG-IP users
into accessing malicious links and reflect a spoofed error message in
the victim's BIG-IP Configuration utility web browser session. This is a
control plane issue; there is no data plane exposure.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
To mitigate this vulnerability, you may take the following actions: When you have finished using the BIG-IP Configuration utility, you should log off and close all instances of your web browser. Do not use the same web browser that you use to manage the BIG-IP Configuration utility for any other purposes, such as browsing the internet. If you must perform both actions on the same client machine, F5 recommends that you do so in separate browsers
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://my.f5.com/manage/s/article/K000161728 |
|
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session. This is a control plane issue; there is no data plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Title | BIG-IP Configuration utility vulnerability | |
| Weaknesses | CWE-451 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: f5
Published:
Updated: 2026-09-02T17:55:45.119Z
Reserved: 2026-07-24T22:40:21.245Z
Link: CVE-2026-63020
No data.
Status : Received
Published: 2026-09-02T16:17:18.400
Modified: 2026-09-02T18:20:59.640
Link: CVE-2026-63020
No data.
OpenCVE Enrichment
No data.
-
CWE-451
User Interface (UI) Misrepresentation of Critical Information