Vulnerability Details CVE-2026-20916
An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG-IQ system.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 27.7%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2026-20916
-
cpe:2.3:a:f5:big-iq_centralized_management:8.4.0