CVE-2026-22549
Unknown
Unknown - Not Provided
Excessive Permissions Vulnerability in F5 BIG-IP Container Ingress
Publication date: 2026-02-04
Last updated on: 2026-02-13
Assigner: F5 Networks
Description
Description
A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive permissions to read cluster secrets.Β Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| f5 | big-ip_container_ingress_services | From 1.0.0 (inc) to 1.14.0 (inc) |
| f5 | big-ip_container_ingress_services | From 2.0.0 (inc) to 2.2.0.2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-250 | The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in F5 BIG-IP Container Ingress Services and may allow users with certain permissions to read cluster secrets that they should not have access to.
How can this vulnerability impact me? :
The vulnerability could lead to unauthorized access to sensitive cluster secrets, potentially exposing confidential information and increasing the risk of further attacks or misuse of the cluster environment.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
I don't know
How can this vulnerability be detected on my network or system? Can you suggest some commands?
I don't know
What immediate steps should I take to mitigate this vulnerability?
I don't know
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70