Sceawere
Vulnerability Detail
CVE-2026-94127UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
BIG-IP APM OAuth RCE
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 3h ago
- Vendor
- F5
- Product
- BIG-IP
- Attack Type
- CWE-122 Heap-based Buffer Overflow
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-09-22T15:17:24.313Z",
"pubdate": "2026-09-22T15:17:24.313Z",
"executiveSummary": "This vulnerability is a critical remote code execution (RCE) flaw impacting F5 BIG-IP systems configured with Access Policy Manager (APM) and an OAuth profile.\nThe vulnerability resides within the data plane processing of specific malicious traffic, allowing unauthenticated attackers to execute arbitrary code with the privileges of the affected service.\nThe scope includes BIG-IP systems operating in Appliance mode, emphasizing that the vulnerability is triggered via direct interaction with the data plane rather than the management control plane.\nThe risk is severe, as successful exploitation facilitates full system compromise without requiring prior authentication, potentially leading to unauthorized data exfiltration, lateral movement, or complete loss of system integrity.\nThe vulnerability hinges on the intersection of the APM access policy engine and the OAuth validation framework during the processing of inbound requests.\nDefensive posture requires immediate attention to vendor-supplied security advisories and the implementation of recommended configuration changes to restrict attack vectors.",
"technicalDetails": "The root cause of this vulnerability lies in the improper sanitization and handling of specific inbound traffic headers or payloads when an OAuth profile is actively bound to a BIG-IP APM-enabled virtual server.\nThe flaw manifests within the data plane, where the BIG-IP system evaluates incoming requests against the configured APM access policies and OAuth validation logic. When the system processes a maliciously crafted request, the interaction between the APM policy engine and the OAuth handling component triggers a memory corruption or injection vulnerability.\nThe exploitation flow begins with an unauthenticated attacker sending a specifically crafted request to a virtual server that has both an APM policy and an OAuth profile configured. As the request is parsed, the internal components responsible for OAuth authentication fail to safely process the provided data, resulting in a transition into a code-execution state.\nBecause the vulnerable component operates at the data plane level, the execution occurs within the context of the TMM (Traffic Management Microkernel) or related user-mode helper processes depending on the specific architecture. Successful exploitation permits the attacker to bypass access controls and execute arbitrary system-level commands.\nThe vulnerability is agnostic to the control plane, meaning that traditional management-side protections may not mitigate the risk of data plane exploitation. The impact is absolute in terms of system execution; once arbitrary code is executed, an attacker can escalate privileges, deploy persistent backdoors, or compromise internal network segments reachable through the BIG-IP proxy.\nThe vulnerability is notably impactful in Appliance mode, as the limited surface area of these systems does not provide immunity against data plane traffic manipulation. The absence of authentication requirements makes this a high-probability target for automated exploitation tools targeting exposed virtual servers.\nDetailed analysis suggests that the defect resides in how the OAuth component interacts with the underlying APM flow state. An attacker can leverage this by manipulating fields expected by the OAuth provider or the internal APM token management service to trigger a buffer overflow or logic error, subsequently redirecting execution flow to attacker-controlled shellcode or system binaries."
}