CVE-2026-67281: Unauthenticated file read in Mikrotik RouterOS
RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving path dereferences this pointer with sufficient rights, then supply parent-directory components in an encrypted URI to escape the WebFig file namespace and disclose root-owned files, including configuration stores containing credentials.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.23.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.24.2
Event History
Frequently Asked Questions
Does exploitation require valid RouterOS credentials?
No. The vulnerable /jsproxy path can be reached by an unauthenticated attacker, who can manipulate allocator state so a stale principal pointer is used during file authorization.
Which RouterOS versions include a fix?
The issue was fixed in 6.49.21 (Lont-term), 7.23.4 (Lont-term), and 7.24.2 (Stable).
What can an attacker access if exploitation succeeds?
An attacker can escape the WebFig file namespace with parent-directory components in an encrypted URI and read root-owned files. This can include configuration stores containing credentials.