CVE-2026-16347: Improper restriction of excessive authentication attempts in MikroTik RouterOS and Cloud Hosted Router
MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful rate-limiting, account lockout, or source-based restrictions, allowing repeated authentication failures to proceed without defensive response. In some versions, a fixed per-connection delay is present, but it can be bypassed through concurrent sessions, resulting in continued high-volume attempts. This deficiency increases the risk that an attacker could eventually obtain valid credentials and gain unauthorized access to administrative services.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16347?
CVE-2026-16347 has a high severity rating of 8.8.
How do I fix CVE-2026-16347?
To fix CVE-2026-16347, implement strong rate-limiting, account lockout mechanisms, and enhance API authentication safeguards.
What type of systems are affected by CVE-2026-16347?
CVE-2026-16347 affects MikroTik RouterOS and MikroTik Cloud Hosted Router.
What is the risk posed by CVE-2026-16347?
CVE-2026-16347 poses a risk due to insufficient protections against excessive authentication attempts, which can lead to unauthorized access.
Is CVE-2026-16347 exploit available?
The exploit for CVE-2026-16347 is possible due to the lack of effective safeguards against repeated authentication failures.