LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-40631

CVE-2026-40631 - Vulnerability Analysis

HighCVSS: 8.7

Last Updated: May 13, 2026

F5 BIG-IP - Broken Access Control

Published: May 13, 2026Updated: May 13, 2026Remote Exploitable

Overview

F5 BIG-IP contains a broken access control vulnerability caused by authenticated attackers with Resource Administrator or Administrator roles modifying configuration objects through iControl SOAP, letting them escalate privileges, exploit requires authenticated admin roles.

Severity & Score

Severity: High
CVSS Score: 8.7
EPSS Score: 5.1%(Probability of exploitation in next 30 days)

Impact

Authenticated attackers with admin roles can escalate privileges by modifying configuration objects.

Mitigation

Update to the latest supported version.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
May 13, 2026

🟠 CVE-2026-40631 - High (8.7) An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) ... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-40631/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
May 13, 2026

🟠 CVE-2026-40631 - High (8.7) An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) ... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-40631/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-40631
Severity
High
CVSS Score
8.7
Type
broken_access_control
Status
unconfirmed
EPSS
5.1%
Social Posts
2

CWE

  • CWE-552

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

EPSS Score

5.1%Probability of exploitation in the next 30 days