
Privilege escalation
A user obtains more permissions than those granted: all dojo articles on this topic.
Image generated locally with ComfyUI from randomly selected elements. How the images are created

Path traversal in the RouterOS container package
CVE-2026-89021 is a path traversal vulnerability in the RouterOS container package that allows an authenticated attacker to write, delete, or create links to files outside the container root without starting it. It affects versions prior to 7.24.2; the fix is not planned for the 7.23.x long-term branch. If you use the container package in device-mode, update to a stable version 7.24.2 or higher, or disable the service.
SecurityUnauthorized command execution via SSH
CVE-2026-86060 is a critical vulnerability in the RouterOS SSH server that allows unauthenticated privilege escalation. It affects versions prior to 6.49.21, 7.23.4, and 7.24.2. It is listed in the CISA KEV catalog and must be patched immediately.
SecuritySession Management Flaw in RouterOS API
CVE-2026-14227 is an Insufficient Session Expiration vulnerability in the RouterOS API that allows authenticated sessions to retain elevated privileges even after rights are reduced or the timeout is exceeded. It affects all RouterOS versions with the API enabled and reachable from untrusted networks. Immediate mitigation consists of disabling the API if not required or restricting access to authorized hosts only, pending a corrective release.
SecurityUnauthorized access to the REST API in RouterOS
CVE-2023-41570 is an access control vulnerability in the RouterOS REST API that allows an authenticated user with low privileges to access sensitive data. It affects versions 7.1 through 7.11. Updating to version 7.12 or later resolves the issue; alternatively, you must restrict access to the REST API to trusted hosts only.
SecurityArbitrary code execution on RouterOS
CVE-2023-30799 is a privilege escalation vulnerability that allows an authenticated attacker with an admin account to obtain super-admin privileges and execute arbitrary code. It affects stable versions of RouterOS prior to 6.49.7 and long-term versions up to and including 6.48.6. Updating to a patched version is the primary measure to mitigate the risk.
SecurityCritical vulnerability in the RouterOS container package
CVE-2022-34960 is a critical vulnerability (CVSS 9.8) in the MikroTik RouterOS 7.4beta4 container package that allows an attacker to mount arbitrary files at any location on the host device. It exclusively affects administrators who have installed and enabled the container package in device mode. Immediate mitigation consists of updating to a fixed version or disabling the service if not used.
SecurityArbitrary directory creation in RouterOS
CVE-2019-3976 allows an authenticated user to create an arbitrary directory and enable the developer shell by installing a malicious package. It affects RouterOS 6.45.6 Stable and earlier, as well as 6.44.5 Long-term and earlier. The administrator must update the firmware to a version later than those indicated to eliminate the risk.