CVE CVE-2026-89021
Severity MEDIUM · CVSS 3.1 6.9 · CVSS 4.0 6.9
Weakness CWE-22, CWE-59
Affected versions < 7.24.2
First non-vulnerable version 7.24.2 (per branch)
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2026-09-14

What is the CVE-2026-89021 vulnerability?

CVE-2026-89021 is a path traversal (CWE-22) and link following (CWE-59) flaw in the OCI/tar image extraction of the container package. By providing a crafted container image with symlinks pointing to arbitrary paths, an attacker can exploit the unsanitized extraction of tar members during import via /container/add to create files with root privileges, create directories, delete files via overlayfs whiteout, and create hardlinks on the persistent data partition, without ever starting the container.

Which RouterOS versions are vulnerable?

RouterOS versions prior to 7.24.2 are vulnerable. The fixed version is 7.24.2. The vendor has confirmed that the fix is not present in the long-term 7.23.x branch: the container binaries in container-7.23.3.npk and container-7.23.4.npk are byte-identical and do not contain the fix. No backport to the long-term branch is planned; the fix is available only in the stable branch starting from 7.24.2.

Is my router at risk?

Your router is exposed if you have installed and enabled the container package in device-mode and the service is reachable from untrusted networks or by users with elevated privileges (PR:H in the CVSS vector). If you do not use the container package, the risk is zero: disable the service to eliminate the attack surface.

Is the CVE-2026-89021 vulnerability actively exploited?

As of the date of this article, CVE-2026-89021 is not listed in the CISA KEV catalog and ENISA does not report it as exploited. There is no evidence of active exploitation.

How to protect the router from CVE-2026-89021?

Update RouterOS to a stable version equal to or higher than 7.24.2. If you cannot update immediately, disable the container package to eliminate the attack surface. Do not install beta or RC versions in production: the fix is available only in the stable branch and the long-term 7.23.x releases remain vulnerable.

Which RouterOS commands are needed to mitigate CVE-2026-89021?

Temporary mitigation: container service

The flaw concerns the container package. It only affects those who have installed and enabled it in device-mode; if you do not use it, disable it.

/system package print where name=container
/container print
# se non usi container: disattiva il pacchetto (richiede un riavvio)
/system package disable container

Updating RouterOS

The only definitive fix is the update. Save the configuration first; the installation reboots the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

Does CVE-2026-89021 require starting the container to be exploited?

No. CVE-2026-89021 can be exploited during the import of the container image via /container/add, without ever starting the container.

Does the long-term 7.23.x branch contain the fix for CVE-2026-89021?

No. The vendor has confirmed that the container binaries in container-7.23.3.npk and container-7.23.4.npk are byte-identical and do not contain the fix. No backport to the long-term branch is planned.

What is the CVSS score for CVE-2026-89021?

The CVSS v3.1 score is 6.9 (MEDIUM), with vector CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:L. The CVSS v4.0 score is also 6.9 (MEDIUM).

Is CVE-2026-89021 in the CISA KEV catalog?

No. As of the date of this article, CVE-2026-89021 is not present in the CISA KEV catalog, and ENISA does not report it as being exploited.

Is disabling the container package sufficient to mitigate CVE-2026-89021?

Yes. If you do not use the container package in device-mode, disabling it removes the attack surface described in CVE-2026-89021.

Official sources