Access of Uninitialized Pointer in MikroTik RouterOS - CVE-2026-67281
Published: September 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose root-owned files.
The vulnerability exists due to access of an uninitialized pointer in the RouterOS WebFig /jsproxy file authorization path when handling crafted encrypted URIs. A remote attacker can prepare the allocator and supply parent-directory components in an encrypted URI to disclose root-owned files.
The stale principal pointer can be dereferenced with sufficient rights to escape the WebFig file namespace.