Improper Enforcement of Behavioral Workflow in MikroTik RouterOS - CVE-2026-67279
Published: September 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to access and modify files in the RouterOS managed file namespace.
The vulnerability exists due to improper enforcement of behavioral workflow in the RouterOS SSH connection protocol when handling a client-requested rekey before user authentication. A remote attacker can open a session channel and send an exec request to access and modify files in the RouterOS managed file namespace.
The accessible files can include support files containing configuration and diagnostic data.