---
id: CVE-2026-41954
title: >-
  Sensitive information disclosure vulnerability exists in the undisclosed
  iControl REST endpoint and TMOS Shell (tmsh) command which may allow an
  authenticated attacker with resource administrator role privileges to view
  sensitive informa…
summary: >-
  Sensitive information disclosure vulnerability exists in the undisclosed
  iControl REST endpoint and TMOS Shell (tmsh) command which may allow an
  authenticated attacker with resource administrator role privileges to view
  sensitive informa…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-200
published: '2026-05-13'
updated: '2026-06-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-41954'
references:
  - url: 'https://my.f5.com/manage/s/article/K32950402'
    label: f5sirt@f5.com
tags:
  - nvd
epss: 0.00404
epssPercentile: 0.31975
ingestedAt: '2026-06-29T13:24:35.039Z'
---

## Overview

Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
