๐Ÿ” CVE Alert

CVE-2026-89021

MEDIUM 6.9

MikroTik RouterOS Path Traversal via Container OCI/tar Image Extraction

CVSS Score
6.9
EPSS Score
0.0%
EPSS Percentile
0th

MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a crafted container image with symlinks pointing to arbitrary paths. Attackers can exploit unsanitized tar member path extraction during container import via /container/add to achieve root-privileged file creation, directory creation, file deletion via overlayfs whiteout, and hardlink creation on the persistent data partition without ever starting the container. The 7.23.x long-term branch does not contain this fix; the container binaries in container-7.23.3.npk and container-7.23.4.npk are byte-identical, and there is no fixed long-term release at the time of publication.

CWE CWE-59 CWE-22
Vendor mikrotik
Product routeros
Published Sep 14, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for mikrotik routeros

Be the first to know when new medium vulnerabilities affecting mikrotik routeros are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Changed
Confidentiality
None
Integrity
High
Availability
Low

Affected Versions

MikroTik / RouterOS
0 < 7.24.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
mikrotik.com: https://mikrotik.com/supportsec/september-2026-vulnerability vulncheck.com: https://www.vulncheck.com/advisories/mikrotik-routeros-path-traversal-via-container-oci-tar-image-extraction

Credits

Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc.