CVE-2026-42780 Details
Description
A directory traversal vulnerability exists in BIG-IP SSL Orchestrator that allows an authenticated attacker with high privilege to overwrite, delete or corrupt arbitrary local files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
A directory traversal vulnerability in F5 BIG-IP SSL Orchestrator allows authenticated attackers with high privileges to overwrite, delete, or corrupt arbitrary local files. This vulnerability affects specific versions of BIG-IP SSL Orchestrator that have not reached End of Technical Support (EoTS). The issue arises from improper limitations on file path handling, enabling unauthorized file manipulation. Exploitation of this vulnerability is a control plane issue, with no exposure to the data plane.
Users can upgrade to BIG-IP SSL Orchestrator versions 21.0.0.1, 17.5.1.4, or 17.1.3.1 to address this vulnerability. For more information on managing BIG-IP product hotfixes, refer to the F5 article K13123.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://my.f5.com/manage/s/article/K000149743 | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| f5 big-ip ssl orchestrator | >= 17.1.0, <= 17.1.3 >= 17.5.0, <= 17.5.1 21.0.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 23, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 13, 2026 | New CVE Received | [email protected] |