Improper Enforcement of Behavioral Workflow in MikroTik RouterOS - CVE-2026-67279

 

Improper Enforcement of Behavioral Workflow in MikroTik RouterOS - CVE-2026-67279

Published: September 6, 2026


Vulnerability identifier: #VU147169
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-67279
CWE-ID: CWE-841
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to access and modify files in the RouterOS managed file namespace.

The vulnerability exists due to improper enforcement of behavioral workflow in the RouterOS SSH connection protocol when handling a client-requested rekey before user authentication. A remote attacker can open a session channel and send an exec request to access and modify files in the RouterOS managed file namespace.

The accessible files can include support files containing configuration and diagnostic data.


Affected software

MikroTik RouterOS

How to mitigate CVE-2026-67279

Install security update from vendor's website.

MikroTik RouterOS - addressed in versions 6.49.21, 7.23.4, 7.24.2

External References

Related Security Bulletins