Session Management Flaw in MikroTik RouterOS API
CVE-2026-14227
6.9MEDIUM
What is CVE-2026-14227?
An API session management flaw in MikroTik RouterOS with the API enabled exposes users to the risk of insufficient session expiration. This vulnerability allows active sessions to maintain their previous permission levels even after an inactivity timeout or changes in user group settings. Consequently, a user whose permissions have been downgraded may still access sensitive information, posing significant security risks.
Affected Version(s)
RouterOS All versions
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Andre Santos reported this vulnerability to CISA.
