CVE-2026-63020 PUBLISHED

BIG-IP Configuration utility vulnerability

Assigner: f5
Reserved: 24.07.2026 Published: 02.09.2026 Updated: 02.09.2026

A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages 

Impact:

An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session. This is a control plane issue; there is no data plane exposure.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 2.3

Product Status

Vendor F5
Product BIG-IP
Versions Default: unknown
  • affected from 21.1.0 to 21.1.0.1 (excl.)
  • affected from 21.0.0 to 21.0.0.3 (excl.)
  • affected from 17.5.0 to 17.5.1.8 (excl.)
  • affected from 17.1.0 to 17.1.3.4 (excl.)

Workarounds

To mitigate this vulnerability, you may take the following actions:

When you have finished using the BIG-IP Configuration utility, you should log off and close all instances of your web browser. Do not use the same web browser that you use to manage the BIG-IP Configuration utility for any other purposes, such as browsing the internet. If you must perform both actions on the same client machine, F5 recommends that you do so in separate browsers

Credits

  • F5 acknowledges Michał Majchrowicz, Marcin Wyczechowski and Piotr Zdunek (members of the AFINE Team) for bringing this issue to our attention and following the highest standards of coordinated disclosure. finder

References

Problem Types

  • CWE-451: User Interface (UI) Misrepresentation of Critical Information CWE