Impact:
This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
An iRule is available upon request. Open a ticket with F5 support to request this.
| Link | Providers |
|---|---|
| https://my.f5.com/manage/s/article/K000162605 |
|
Tue, 22 Sep 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
F5
F5 big-ip |
|
| Vendors & Products |
F5
F5 big-ip |
Tue, 22 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Title | BIG-IP APM OAuth vulnerability | |
| Weaknesses | CWE-122 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: f5
Published:
Updated: 2026-09-22T14:17:42.730Z
Reserved: 2026-09-20T17:39:19.975Z
Link: CVE-2026-94127
No data.
Status : Received
Published: 2026-09-22T15:17:24.313
Modified: 2026-09-22T15:17:24.313
Link: CVE-2026-94127
No data.
OpenCVE Enrichment
Updated: 2026-09-22T16:15:08Z