Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-35062

CVE-2026-35062: iControl SOAP Information Disclosure Flaw

CVE-2026-35062 is an information disclosure vulnerability in iControl SOAP allowing authenticated users to access other account information. This article covers the technical details, affected versions, and mitigation.

Published:

CVE-2026-35062 Overview

CVE-2026-35062 is an information disclosure vulnerability affecting F5 products that expose the iControl SOAP API. An authenticated iControl SOAP user can obtain information belonging to other accounts on the same system. The flaw is classified under [CWE-266: Incorrect Privilege Assignment], indicating that account-scoped data is accessible beyond its intended privilege boundary. F5 notes that software versions which have reached End of Technical Support (EoTS) are not evaluated. The issue requires network access to the management interface and valid low-privilege credentials, making it most relevant in multi-tenant or multi-administrator F5 deployments.

Critical Impact

An authenticated, low-privileged iControl SOAP user can read data belonging to other accounts, undermining administrative separation on shared F5 systems.

Affected Products

  • F5 products exposing the iControl SOAP interface (specific versions enumerated in F5 advisory K000159021)
  • Supported F5 BIG-IP software branches as listed by the vendor
  • F5 software versions that have not reached End of Technical Support (EoTS)

Discovery Timeline

  • 2026-05-13 - CVE-2026-35062 published to NVD
  • 2026-05-13 - Last updated in NVD database

Technical Details for CVE-2026-35062

Vulnerability Analysis

The vulnerability resides in the iControl SOAP API, F5's XML-based management interface used to administer BIG-IP systems. An authenticated SOAP user can issue requests that return account information not associated with their own user context. This breaks the role and account isolation model that F5 administrators rely on to delegate access. The defect is mapped to [CWE-266], which describes a condition where a subject is granted privileges or visibility beyond what its role should permit. Disclosed account data may include identifiers, role assignments, or other attributes that aid follow-on attacks such as targeted credential abuse or privilege escalation attempts against higher-privileged accounts.

Root Cause

The root cause is improper enforcement of per-account access controls within affected iControl SOAP methods. The API does not consistently validate that the calling principal is authorized to view the requested account's information before returning it. As a result, an authorization check that should restrict responses to the caller's own context is either missing or incorrectly scoped.

Attack Vector

The attack vector is network-based against the F5 management plane. An attacker must first authenticate to iControl SOAP with valid, low-privilege credentials. The attacker then issues crafted SOAP requests targeting account-related methods to retrieve information about users other than themselves. No user interaction is required, and the impact is limited to confidentiality of account data on the affected system.

No verified public proof-of-concept code is available. Refer to the F5 Security Article K000159021 for vendor technical details.

Detection Methods for CVE-2026-35062

Indicators of Compromise

  • Unexpected iControl SOAP requests from accounts that do not normally query user or account-management endpoints.
  • Repeated SOAP calls enumerating account identifiers or user lists from a single low-privilege session.
  • Authentication events for low-privilege F5 accounts followed by spikes in management API traffic.

Detection Strategies

  • Enable and forward F5 audit logs covering iControl SOAP authentication and method invocation to a central log platform.
  • Baseline expected SOAP method usage per account, then alert on deviations such as low-privilege users invoking account-listing methods.
  • Correlate management-plane authentication events with subsequent API calls to identify enumeration patterns consistent with abuse of this flaw.

Monitoring Recommendations

  • Monitor access to the F5 management interface and restrict it to trusted administrative networks.
  • Track the volume and diversity of SOAP method calls per account to detect reconnaissance behavior.
  • Review service account activity on F5 devices for anomalous account-information queries outside normal automation windows.

How to Mitigate CVE-2026-35062

Immediate Actions Required

  • Apply the fixed software versions identified in F5 Security Article K000159021 on all affected BIG-IP systems.
  • Inventory F5 instances and confirm none are running EoTS software, which the vendor does not evaluate for this CVE.
  • Audit existing iControl SOAP accounts and remove or rotate credentials for any unused or shared low-privilege users.

Patch Information

F5 has published guidance and fixed versions in advisory K000159021. Administrators should consult the advisory to map their current BIG-IP version to the recommended fixed release and schedule upgrades accordingly. Systems on End of Technical Support branches must be migrated to supported versions, since the vendor does not provide fixes for EoTS software.

Workarounds

  • Restrict iControl SOAP access to a dedicated, network-segmented management VLAN reachable only by authorized administrators.
  • Limit iControl SOAP usage to the minimum set of accounts required for automation, and apply least-privilege role assignments.
  • Enforce strong authentication and credential rotation for all F5 management accounts to reduce the value of any leaked account data.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.