Improper Neutralization of Argument Delimiters in a Command in MikroTik RouterOS - CVE-2026-86060

 

Improper Neutralization of Argument Delimiters in a Command in MikroTik RouterOS - CVE-2026-86060

Published: September 6, 2026


Vulnerability identifier: #VU147171
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-86060
CWE-ID: CWE-88
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper neutralization of argument delimiters in the RouterOS SSH login path when processing a username beginning with a prohibited character. A remote attacker can submit a crafted username to change the trusted RouterOS policy mask and escalate privileges.

Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.


Affected software

MikroTik RouterOS

How to mitigate CVE-2026-86060

Install security update from vendor's website.

MikroTik RouterOS - addressed in versions 6.49.21, 7.23.4, 7.24.2

External References

Related Security Bulletins