Database/Control plane, storage & DevOps
F5 BIG-IP (iHealth command / tmsh restricted shell): An authenticated attacker with at least a resource-administrator
Impact
An authenticated attacker with at least a resource-administrator role can use the iHealth command to break out of the restricted tmsh shell and get a full bash shell on the device — this specifically defeats BIG-IP's Appliance mode, the hardened mode operators use to lock admins out of the underlying OS on shared/regulated deployments.
Who can reach it
Requires an authenticated account with resource-administrator role (not full root/admin) — the attack is a privilege-escalation/shell-escape from a role that was supposed to be constrained.
What to do
Software upgrade to the fixed BIG-IP release per F5 K000154647. Part of the same October 2025 remediation batch as CVE-2025-53521 — apply in the same maintenance window. This specifically matters for shared/managed BIG-IP deployments that rely on Appliance mode to keep administrators out of shell access.
References
Related entries
- GitLab CE/EE: stored XSS in analytics dashboard pagination controlsCVE-2026-15216 · GitLab CE/EE (analytics dashboard pagination controls)High
- GitLab CE/EE: stored XSS in analytics dashboard table cell renderingCVE-2026-15217 · GitLab CE/EE (analytics dashboard table cell rendering)High
- Sigstore Fulcio: OIDC discovery follows cross-host redirects and leaks ServiceAccount tokensCVE-2026-49478 · Sigstore Fulcio (OIDC discovery HTTP client, cross-host redirects)High
- Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD and LIP-ME201C (through 8.4.18, LINX-A64): An out-of-boundsCVE-2026-55732 · Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD and LIP-ME201C (through 8.4.18, LINX-A64)High
- Netty: OpenSSL client path silently skips TLS hostname verification on Java 25+CVE-2026-62243 · Netty io.netty:netty-handler (SslProvider.OPENSSL client-side hostname verification)High
- Pure Storage FlashArray Purity (data path information exposure): Insufficient filtering on certain data paths exposesCVE-2026-6445 · Pure Storage FlashArray Purity (data path information exposure)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.