PT-2026-40656 · F5 · Big-Ip

Published

2026-05-13

·

Updated

2026-05-17

·

CVE-2026-40703

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions F5 BIG-IP versions prior to 17.1.3.1 F5 BIG-IP versions prior to 17.5.1.4
Description A cross-site request forgery (CSRF) issue exists in the dashboard of the BIG-IP Configuration utility. CSRF is a flaw that allows an attacker to induce a user into performing actions they did not intend to do on a web application where they are currently authenticated.
Recommendations Update to version 17.1.3.1 or later. Update to version 17.5.1.4 or later.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2026-40703

Affected Products

Big-Ip