Status: UPDATED
| Advisory ID: CVE-2026-67276
Key Details
| CVE | CVE-2026-67276 |
| CVSS Score / Version | 8.1 (High) / CVSS v3.1 |
| Updated | 2026-09-25 |
| CVSS Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is high; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | MikroTik RouterOS |
| Classified as | CWE-347 (Improper Verification of Cryptographic Signature) |
Affected Products, Subsystems & Sectors
| Subsystems | Industrial Network - Routers/Firewalls |
| Sectors | Multi-sector |
What to Know
RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)
What to Do
Monitor MikroTik's web page for any future patch releases. See vendor advisory link below.
References