← All Advisories

CVE-2026-67281

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-67281

Key Details

CVECVE-2026-67281
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-09-25
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is none.
Affected productsMikroTik RouterOS
Classified asCWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
MikroTikRouterOS
SubsystemsIndustrial Network - Routers/Firewalls
SectorsMulti-sector

What to Know

RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving path dereferences this pointer with sufficient rights, then supply parent-directory components in an encrypted URI to escape the WebFig file namespace and disclose root-owned files, including configuration stores containing credentials.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)

What to Do

Monitor MikroTik's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-67281
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-67281
Vendor advisoryhttps://mikrotik.com/supportsec/september-2026-vulnerability/