Improper Neutralization of Argument Delimiters in a Command in MikroTik RouterOS - CVE-2026-86060
Published: September 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper neutralization of argument delimiters in the RouterOS SSH login path when processing a username beginning with a prohibited character. A remote attacker can submit a crafted username to change the trusted RouterOS policy mask and escalate privileges.
Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.