Vulnerability Details CVE-2026-42780
A directory traversal vulnerability exists in BIG-IP SSL Orchestrator that allows an authenticated attacker with high privilege to overwrite, delete or corrupt arbitrary local files.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 54.7%
CVSS Severity
CVSS v3 Score 4.9
Products affected by CVE-2026-42780
-
cpe:2.3:a:f5:big-ip_ssl_orchestrator:17.1.0
-
cpe:2.3:a:f5:big-ip_ssl_orchestrator:17.1.0.1
-
cpe:2.3:a:f5:big-ip_ssl_orchestrator:17.1.0.2
-
cpe:2.3:a:f5:big-ip_ssl_orchestrator:17.1.1
-
cpe:2.3:a:f5:big-ip_ssl_orchestrator:17.1.1.3
-
cpe:2.3:a:f5:big-ip_ssl_orchestrator:17.1.1.4
-
cpe:2.3:a:f5:big-ip_ssl_orchestrator:17.1.2
-
cpe:2.3:a:f5:big-ip_ssl_orchestrator:17.1.2.1
-
cpe:2.3:a:f5:big-ip_ssl_orchestrator:17.1.2.2
-
cpe:2.3:a:f5:big-ip_ssl_orchestrator:17.1.3
-
cpe:2.3:a:f5:big-ip_ssl_orchestrator:17.5.0
-
cpe:2.3:a:f5:big-ip_ssl_orchestrator:17.5.1
-
cpe:2.3:a:f5:big-ip_ssl_orchestrator:21.0.0