Back

CRITICAL KEV

SSH session privilege manipulation via a crafted username in Mikrotik RouterOS

Published Sep 5, 2026 ·Due Sep 13, 2026

Description

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CERT-PL
Published Sep 5, 2026
Updated Sep 11, 2026
Reserved Sep 4, 2026
CISA Vulnrichment
Updated Sep 10, 2026
NVD
Status Analyzed
Modified Sep 11, 2026
Red Hat
Severity n/a
Public date n/a