CVE-2026-67279: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.
Other sources
RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MikroTik RouterOSto a version that resolves this vulnerability.Fixed in 6.49.21 - Upgrade
Upgrade
MikroTik RouterOSto a version that resolves this vulnerability.Fixed in 7.23.4 - Upgrade
Upgrade
MikroTik RouterOSto a version that resolves this vulnerability.Fixed in 7.24.2
Event History
Frequently Asked Questions
Which RouterOS releases contain the fix?
The issue was fixed in RouterOS 6.49.21 Long-term, 7.23.4 Long-term, and 7.24.2 Stable.
What does an attacker need to do to exploit this issue?
An unauthenticated SSH client must request a rekey before attempting user authentication. The server can then enter the connection protocol, allowing the client to open a session channel and submit an exec request.
What access could an attacker obtain through the vulnerable SSH service?
The attacker can cause the server to dispatch commands without authentication. This enables creation, overwriting, and reconstruction of files in the RouterOS managed file namespace, including support files with configuration and diagnostic data.