← Back to Feed

MikroTik RouterOS

CVE-2026-14227

July 30, 2026 · CISA (US-CERT) · Severity: CRITICAL

MikroTik RouterOS has a session management flaw that allows API sessions to retain permissions after inactivity or user-group changes. An authenticated user with reduced privileges may still access sensitive data, such as the WireGuard private key. The vendor recommends logging out users fully after permission changes to enforce new policies.

Key Takeaways

  • Insufficient session expiration in MikroTik RouterOS API may retain permissions.
  • Low-privilege API access can extract the WireGuard private key in plaintext.
  • Administrators should fully log out users after downgrading permissions.
☕ Buy a Coffee