Sceawere

Vulnerability Detail

CVE-2026-94127UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

BIG-IP APM OAuth RCE

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
3h ago
Vendor
F5
Product
BIG-IP
Attack Type
CWE-122 Heap-based Buffer Overflow
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-09-22T15:17:24.313Z",
  "pubdate": "2026-09-22T15:17:24.313Z",
  "executiveSummary": "This vulnerability is a critical remote code execution (RCE) flaw impacting F5 BIG-IP systems configured with Access Policy Manager (APM) and an OAuth profile.\nThe vulnerability resides within the data plane processing of specific malicious traffic, allowing unauthenticated attackers to execute arbitrary code with the privileges of the affected service.\nThe scope includes BIG-IP systems operating in Appliance mode, emphasizing that the vulnerability is triggered via direct interaction with the data plane rather than the management control plane.\nThe risk is severe, as successful exploitation facilitates full system compromise without requiring prior authentication, potentially leading to unauthorized data exfiltration, lateral movement, or complete loss of system integrity.\nThe vulnerability hinges on the intersection of the APM access policy engine and the OAuth validation framework during the processing of inbound requests.\nDefensive posture requires immediate attention to vendor-supplied security advisories and the implementation of recommended configuration changes to restrict attack vectors.",
  "technicalDetails": "The root cause of this vulnerability lies in the improper sanitization and handling of specific inbound traffic headers or payloads when an OAuth profile is actively bound to a BIG-IP APM-enabled virtual server.\nThe flaw manifests within the data plane, where the BIG-IP system evaluates incoming requests against the configured APM access policies and OAuth validation logic. When the system processes a maliciously crafted request, the interaction between the APM policy engine and the OAuth handling component triggers a memory corruption or injection vulnerability.\nThe exploitation flow begins with an unauthenticated attacker sending a specifically crafted request to a virtual server that has both an APM policy and an OAuth profile configured. As the request is parsed, the internal components responsible for OAuth authentication fail to safely process the provided data, resulting in a transition into a code-execution state.\nBecause the vulnerable component operates at the data plane level, the execution occurs within the context of the TMM (Traffic Management Microkernel) or related user-mode helper processes depending on the specific architecture. Successful exploitation permits the attacker to bypass access controls and execute arbitrary system-level commands.\nThe vulnerability is agnostic to the control plane, meaning that traditional management-side protections may not mitigate the risk of data plane exploitation. The impact is absolute in terms of system execution; once arbitrary code is executed, an attacker can escalate privileges, deploy persistent backdoors, or compromise internal network segments reachable through the BIG-IP proxy.\nThe vulnerability is notably impactful in Appliance mode, as the limited surface area of these systems does not provide immunity against data plane traffic manipulation. The absence of authentication requirements makes this a high-probability target for automated exploitation tools targeting exposed virtual servers.\nDetailed analysis suggests that the defect resides in how the OAuth component interacts with the underlying APM flow state. An attacker can leverage this by manipulating fields expected by the OAuth provider or the internal APM token management service to trigger a buffer overflow or logic error, subsequently redirecting execution flow to attacker-controlled shellcode or system binaries."
}
CVE-2026-94127: BIG-IP APM OAuth RCE (CRITICAL Severity, CVSS: 9.8) | Sceawere