CVE-2026-14227: Insufficient session expiration in MikroTik RouterOS
An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Session Expiration vulnerability. This could allow active sessions to retain their previous permission set after inactivity timeouts or user‑group changes. As a result, an authenticated user whose permissions have been reduced may continue accessing information.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Operational
In MikroTik RouterOS with the API enabled, when a user’s permissions are downgraded, fully log out (terminate) the affected user so any active sessions cannot retain prior permissions after inactivity timeouts or user-group changes.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14227?
The severity of CVE-2026-14227 is rated as medium with a CVSS score of 4.9.
How does CVE-2026-14227 impact MikroTik RouterOS users?
CVE-2026-14227 can lead to insufficient session expiration, allowing sessions to maintain permissions despite inactivity or changes.
How do I fix CVE-2026-14227?
To address CVE-2026-14227, ensure you update MikroTik RouterOS to the latest version that resolves this vulnerability.
What products are affected by CVE-2026-14227?
CVE-2026-14227 affects MikroTik RouterOS instances with the API enabled.
Is CVE-2026-14227 exploitable remotely?
Yes, CVE-2026-14227 is exploitable over the network due to its nature as an API session-management flaw.