← Vulnerability feed

Vulnerability record · CVE-2024-26026 · published 8 May 2024

CVE-2024-26026: F5 big-ip next central manager sql injection vulnerability

F5 · Big Ip Next Central Manager

An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

7.5 CVSS 3.1 High EPSS 7.2% · top 5.9% CWE-89 · SQL injection
7.5CVSS 3.1 base score
7.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-26026 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.9CVE-2024-39809F5 big-ip next central manager insufficient session expiration vulnerabilityThe Central Manager user session refresh token does not expire when a user logs out.  Note: Software versions which have reached End of Technical Sup…EPSS 0.44%8.7CVE-2025-41399F5 big-ip access policy manager improper resource shutdown vulnerabilityWhen a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests can cause an increase in memory re…EPSS 0.41%8.7CVE-2025-36504F5 big-ip access policy manager allocation without limits vulnerabilityWhen a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses can cause an increase in memory resource utilization…EPSS 0.42%7.5CVE-2024-21793F5 big-ip next central manager sql injection vulnerabilityAn OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which have reached End of Technical Su…EPSS 7.1%7.4CVE-2024-32049F5 big-ip next central manager vulnerabilityBIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instance credentials.  Note: Softwar…EPSS 0.55%7.1CVE-2025-24319F5 big-ip next central manager improper input validation vulnerabilityWhen BIG-IP Next Central Manager is running, undisclosed requests to the BIG-IP Next Central Manager API can cause the BIG-IP Next Central Manager No…EPSS 0.39%6.9CVE-2025-54500F5 big-ip access policy manager allocation without limits vulnerabilityAn HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams…EPSS 0.50%6.8CVE-2024-33612F5 big-ip next central manager improper certificate validation vulnerabilityAn improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impersonate an Instance Provider …EPSS 0.23%

Source: NIST National Vulnerability Database (record CVE-2024-26026), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.