← Back to Feed
MikroTik RouterOS
CVE-2026-14227
July 30, 2026 · CISA (US-CERT) · Severity: CRITICAL
MikroTik RouterOS has a session management flaw that allows API sessions to retain permissions after inactivity or user-group changes. An authenticated user with reduced privileges may still access sensitive data, such as the WireGuard private key. The vendor recommends logging out users fully after permission changes to enforce new policies.
Key Takeaways
- Insufficient session expiration in MikroTik RouterOS API may retain permissions.
- Low-privilege API access can extract the WireGuard private key in plaintext.
- Administrators should fully log out users after downgrading permissions.