{"id":"CVE-2026-41954","title":"Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive informa…","summary":"Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive informa…","severity":"medium","cvss":4.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-200"],"published":"2026-05-13","updated":"2026-06-24","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-41954","references":[{"url":"https://my.f5.com/manage/s/article/K32950402","label":"f5sirt@f5.com"}],"tags":["nvd"],"epss":0.00294,"epssPercentile":0.22307,"ingestedAt":"2026-06-29T13:24:35.039Z","slug":"CVE-2026-41954","body":"## Overview\n\nSensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":27,"depthScoreParts":{"impact":27,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}