🔐 CVE Alert

CVE-2026-67281

UNKNOWN 0.0

Unauthenticated file read in Mikrotik RouterOS

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving path dereferences this pointer with sufficient rights, then supply parent-directory components in an encrypted URI to escape the WebFig file namespace and disclose root-owned files, including configuration stores containing credentials.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)

CWE CWE-824 CWE-22
Vendor mikrotik
Product routeros
Published Sep 5, 2026
Last Updated Sep 8, 2026
Stay Ahead of the Next One

Get instant alerts for mikrotik routeros

Be the first to know when new unknown vulnerabilities affecting mikrotik routeros are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Mikrotik / RouterOS
7.24 < 7.24.2 7.20 < 7.23.4

References

NVD ↗ CVE.org ↗ EPSS Data ↗
cert.pl: https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve cert.pl: https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/ npratley.net: https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/ mikrotik.com: https://mikrotik.com/supportsec/september-2026-vulnerability/ forum.mikrotik.com: https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801 forum.mikrotik.com: https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800

Credits

Sławomir Rozbicki (CERT.PL)