CVE Details
CVE-2026-86060
MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
Published: 2026-09-10
CVSS: 9.2 CRITICAL
Product: MikroTik RouterOS
Due Date: 2026-09-13
MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation.
GitHub PoC
Warning: GitHub PoC repositories are unverified. Some may be fake
or contain malware. Use caution and review code before running anything.
FIRST EPSS
EPSS estimates the probability of exploitation in the next 30 days. Higher values indicate higher likelihood of real-world exploitation.
Timeline
CVE Stalker
KEV
MITRE
GitHub
FIRST (EPSS)
MITRE
CVSS
SSVC
References
Show Raw Data
| Key | Remaining Key | Value |
|---|---|---|
| dataType | CVE_RECORD | |
| dataVersion | 5.2 | |
| cveMetadata > | cveId | CVE-2026-86060 |
| cveMetadata > | assignerOrgId | 4bb8329e-dd38-46c1-aafb-9bf32bcb93c6 |
| cveMetadata > | state | PUBLISHED |
| cveMetadata > | assignerShortName | CERT-PL |
| cveMetadata > | dateReserved | 2026-09-04T19:32:24.461Z |
| cveMetadata > | datePublished | 2026-09-05T20:00:59.107Z |
| cveMetadata > | dateUpdated | 2026-09-10T19:58:23.426Z |
| containers > | cna > providerMetadata > orgId | 4bb8329e-dd38-46c1-aafb-9bf32bcb93c6 |
| containers > | cna > providerMetadata > shortName | CERT-PL |
| containers > | cna > providerMetadata > dateUpdated | 2026-09-05T20:41:30.072Z |
| containers > | cna > title | SSH session privilege manipulation via a crafted username in Mikrotik RouterOS |
| containers > | cna > problemTypes > 0 > descriptions > 0 > lang | en |
| containers > | cna > problemTypes > 0 > descriptions > 0 > cweId | CWE-88 |
| containers > | cna > problemTypes > 0 > descriptions > 0 > description | CWE-88 Improper neutralization of argument delimiters in a command ('argument injection') |
| containers > | cna > problemTypes > 0 > descriptions > 0 > type | CWE |
| containers > | cna > affected > 0 > vendor | Mikrotik |
| containers > | cna > affected > 0 > product | RouterOS |
| containers > | cna > affected > 0 > versions > 0 > status | affected |
| containers > | cna > affected > 0 > versions > 0 > version | 7.24 |
| containers > | cna > affected > 0 > versions > 0 > lessThan | 7.24.2 |
| containers > | cna > affected > 0 > versions > 0 > versionType | custom |
| containers > | cna > affected > 0 > versions > 1 > status | affected |
| containers > | cna > affected > 0 > versions > 1 > version | 7.0.0 |
| containers > | cna > affected > 0 > versions > 1 > lessThan | 7.23.4 |
| containers > | cna > affected > 0 > versions > 1 > versionType | custom |
| containers > | cna > affected > 0 > versions > 2 > status | affected |
| containers > | cna > affected > 0 > versions > 2 > version | 6.0.0 |
| containers > | cna > affected > 0 > versions > 2 > lessThan | 6.49.21 |
| containers > | cna > affected > 0 > versions > 2 > versionType | custom |
| containers > | cna > affected > 0 > defaultStatus | unaffected |
| containers > | cna > cpeApplicability > 0 > operator | OR |
| containers > | cna > cpeApplicability > 0 > nodes > 0 > operator | OR |
| containers > | cna > cpeApplicability > 0 > nodes > 0 > negate | False |
| containers > | cna > cpeApplicability > 0 > nodes > 0 > cpeMatch > 0 > vulnerable | True |
| containers > | cna > cpeApplicability > 0 > nodes > 0 > cpeMatch > 0 > criteria | cpe:2.3:a:mikrotik:routeros:*:*:*:*:*:*:*:* |
| containers > | cna > cpeApplicability > 0 > nodes > 0 > cpeMatch > 0 > versionStartIncluding | 7.24 |
| containers > | cna > cpeApplicability > 0 > nodes > 0 > cpeMatch > 0 > versionEndExcluding | 7.24.2 |
| containers > | cna > cpeApplicability > 0 > nodes > 0 > cpeMatch > 1 > vulnerable | True |
| containers > | cna > cpeApplicability > 0 > nodes > 0 > cpeMatch > 1 > criteria | cpe:2.3:a:mikrotik:routeros:*:*:*:*:*:*:*:* |
| containers > | cna > cpeApplicability > 0 > nodes > 0 > cpeMatch > 1 > versionStartIncluding | 7.0.0 |
| containers > | cna > cpeApplicability > 0 > nodes > 0 > cpeMatch > 1 > versionEndExcluding | 7.23.4 |
| containers > | cna > cpeApplicability > 0 > nodes > 0 > cpeMatch > 2 > vulnerable | True |
| containers > | cna > cpeApplicability > 0 > nodes > 0 > cpeMatch > 2 > criteria | cpe:2.3:a:mikrotik:routeros:*:*:*:*:*:*:*:* |
| containers > | cna > cpeApplicability > 0 > nodes > 0 > cpeMatch > 2 > versionStartIncluding | 6.0.0 |
| containers > | cna > cpeApplicability > 0 > nodes > 0 > cpeMatch > 2 > versionEndExcluding | 6.49.21 |
| containers > | cna > descriptions > 0 > lang | en |
| containers > | cna > descriptions > 0 > value | RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable) |
| containers > | cna > descriptions > 0 > supportingMedia > 0 > type | text/html |
| containers > | cna > descriptions > 0 > supportingMedia > 0 > base64 | False |
| containers > | cna > descriptions > 0 > supportingMedia > 0 > value | RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.<div>This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)</div> |
| containers > | cna > references > 0 > url | https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve |
| containers > | cna > references > 0 > tags > 0 | third-party-advisory |
| containers > | cna > references > 1 > url | https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/ |
| containers > | cna > references > 1 > tags > 0 | technical-description |
| containers > | cna > references > 2 > url | https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/ |
| containers > | cna > references > 2 > tags > 0 | exploit |
| containers > | cna > references > 3 > url | https://mikrotik.com/supportsec/september-2026-vulnerability/ |
| containers > | cna > references > 3 > tags > 0 | vendor-advisory |
| containers > | cna > references > 4 > url | https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802 |
| containers > | cna > references > 4 > tags > 0 | release-notes |
| containers > | cna > references > 5 > url | https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801 |
| containers > | cna > references > 5 > tags > 0 | release-notes |
| containers > | cna > references > 6 > url | https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800 |
| containers > | cna > references > 6 > tags > 0 | release-notes |
| containers > | cna > metrics > 0 > format | CVSS |
| containers > | cna > metrics > 0 > scenarios > 0 > lang | en |
| containers > | cna > metrics > 0 > scenarios > 0 > value | GENERAL |
| containers > | cna > metrics > 0 > cvssV4_0 > attackVector | NETWORK |
| containers > | cna > metrics > 0 > cvssV4_0 > attackComplexity | LOW |
| containers > | cna > metrics > 0 > cvssV4_0 > attackRequirements | PRESENT |
| containers > | cna > metrics > 0 > cvssV4_0 > privilegesRequired | NONE |
| containers > | cna > metrics > 0 > cvssV4_0 > userInteraction | NONE |
| containers > | cna > metrics > 0 > cvssV4_0 > vulnConfidentialityImpact | HIGH |
| containers > | cna > metrics > 0 > cvssV4_0 > subConfidentialityImpact | NONE |
| containers > | cna > metrics > 0 > cvssV4_0 > vulnIntegrityImpact | HIGH |
| containers > | cna > metrics > 0 > cvssV4_0 > subIntegrityImpact | NONE |
| containers > | cna > metrics > 0 > cvssV4_0 > vulnAvailabilityImpact | HIGH |
| containers > | cna > metrics > 0 > cvssV4_0 > subAvailabilityImpact | NONE |
| containers > | cna > metrics > 0 > cvssV4_0 > exploitMaturity | NOT_DEFINED |
| containers > | cna > metrics > 0 > cvssV4_0 > Safety | NOT_DEFINED |
| containers > | cna > metrics > 0 > cvssV4_0 > Automatable | NOT_DEFINED |
| containers > | cna > metrics > 0 > cvssV4_0 > Recovery | NOT_DEFINED |
| containers > | cna > metrics > 0 > cvssV4_0 > valueDensity | NOT_DEFINED |
| containers > | cna > metrics > 0 > cvssV4_0 > vulnerabilityResponseEffort | NOT_DEFINED |
| containers > | cna > metrics > 0 > cvssV4_0 > providerUrgency | NOT_DEFINED |
| containers > | cna > metrics > 0 > cvssV4_0 > version | 4.0 |
| containers > | cna > metrics > 0 > cvssV4_0 > baseSeverity | CRITICAL |
| containers > | cna > metrics > 0 > cvssV4_0 > baseScore | 9.2 |
| containers > | cna > metrics > 0 > cvssV4_0 > vectorString | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| containers > | cna > credits > 0 > lang | en |
| containers > | cna > credits > 0 > value | Sławomir Rozbicki (CERT.PL) |
| containers > | cna > credits > 0 > type | finder |
| containers > | cna > source > discovery | INTERNAL |
| containers > | cna > x_generator > engine | Vulnogram 1.0.3 |
| containers > | adp > 0 > metrics > 0 > other > type | ssvc |
| containers > | adp > 0 > metrics > 0 > other > content > id | CVE-2026-86060 |
| containers > | adp > 0 > metrics > 0 > other > content > role | CISA Coordinator |
| containers > | adp > 0 > metrics > 0 > other > content > options > 0 > Exploitation | active |
| containers > | adp > 0 > metrics > 0 > other > content > options > 1 > Automatable | yes |
| containers > | adp > 0 > metrics > 0 > other > content > options > 2 > Technical Impact | total |
| containers > | adp > 0 > metrics > 0 > other > content > version | 2.0.3 |
| containers > | adp > 0 > metrics > 0 > other > content > timestamp | 2026-09-10T19:48:03.827888Z |
| containers > | adp > 0 > metrics > 1 > other > type | kev |
| containers > | adp > 0 > metrics > 1 > other > content > dateAdded | 2026-09-10 |
| containers > | adp > 0 > metrics > 1 > other > content > reference | https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86060 |
| containers > | adp > 0 > references > 0 > url | https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86060 |
| containers > | adp > 0 > references > 0 > tags > 0 | government-resource |
| containers > | adp > 0 > title | CISA ADP Vulnrichment |
| containers > | adp > 0 > providerMetadata > orgId | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| containers > | adp > 0 > providerMetadata > shortName | CISA-ADP |
| containers > | adp > 0 > providerMetadata > dateUpdated | 2026-09-10T19:58:23.426Z |
| containers > | adp > 0 > timeline > 0 > time | 2026-09-10T00:00:00.000Z |
| containers > | adp > 0 > timeline > 0 > lang | en |
| containers > | adp > 0 > timeline > 0 > value | CVE-2026-86060 added to CISA KEV |