Security & Threat Intelligence · 30.07.2026, 17:34 UTC
MikroTik RouterOS
| Schweregrad | info |
|---|---|
| CVE | ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | CISA Advisories ↗ |
| Veröffentlicht | 30.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2026-14227. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to extract the router's WireGuard private key in plaintext using only low‑privilege API access, enabling full VPN impersonation and decryption of all associated traffic. The following versions of MikroTik RouterOS are affected:
RouterOS vers:all/* (CVE-2026-14227)
CVSS Vendor Equipment Vulnerabilities
v3 4.9 MikroTik MikroTik RouterOS Insufficient Session Expiration
Background
Critical Infrastructure Sectors: Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: Latvia
Vulnerabilities
Expand All +
CVE-2026-14227
An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Session Expiration vulnerability. This could allow active sessions to retain their previous permission set after inactivity timeouts or user‑group changes. As a result, an authenticated user whose permissions have been reduced may continue accessing information. View CVE Details
Affected Products MikroTik RouterOS
Vendor:MikroTik Product Version:MikroTik RouterOS: vers:all/* Product Status:known_affected
Remediations MitigationMikroTik recommends administrators to ensure that when a user's permissions are downgraded, the affected user is fully logged out so the new policy can take effect. MitigationFor more information, contact MikroTik (https://mikrotik.com/support).https://mikrotik.com/support
Relevant CWE: CWE-613 Insufficient Session Expiration
Metrics
CVSS Version Base Score Base Severity Vector …