🔐 CVE Alert

CVE-2026-14227

MEDIUM 4.9

Insufficient session expiration in MikroTik RouterOS

CVSS Score
4.9
EPSS Score
0.0%
EPSS Percentile
0th

An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Session Expiration vulnerability. This could allow active sessions to retain their previous permission set after inactivity timeouts or user‑group changes. As a result, an authenticated user whose permissions have been reduced may continue accessing information.

CWE CWE-613
Vendor mikrotik
Product routeros
Published Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for mikrotik routeros

Be the first to know when new medium vulnerabilities affecting mikrotik routeros are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

MikroTik / RouterOS
All versions

References

NVD ↗ CVE.org ↗ EPSS Data ↗
cisa.gov: https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-01

Credits

Andre Santos reported this vulnerability to CISA.