PT-2026-86456 · Mikrotik · Routeros

·

CVE-2026-86060

·

Published

2026-09-02

·

Updated

2026-09-12

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions RouterOS versions prior to 6.49.21 RouterOS versions prior to 7.23.4 RouterOS versions prior to 7.24.2
Description An argument-handling flaw exists in the SSH login path when usernames begin with a prohibited character. This allows an unauthenticated user to reach the RouterOS login helper and change the trusted RouterOS policy mask, resulting in privilege escalation.
Recommendations Update to version 6.49.21 or later for the Long-term release. Update to version 7.23.4 or later for the Long-term release. Update to version 7.24.2 or later for the Stable release.

Exploit

Fix

LPE

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14154
CVE-2026-86060

Affected Products

Routeros