API Authentication Flaw in MikroTik RouterOS
CVE-2026-16347

8.7HIGH

Key Information:

Vendor

Mikrotik

Vendor
CVE Published:
28 July 2026

What is CVE-2026-16347?

CVE-2026-16347 is a vulnerability present in MikroTik RouterOS, a widely used operating system for routers and networking devices. The purpose of RouterOS is to provide robust routing features and network management capabilities for both home and enterprise environments. This specific vulnerability relates to an ineffectual handling of API authentication, which undermines the system's ability to defend against unauthorized access attempts. The lack of effective protective measures such as rate limiting and account lockout enables attackers to launch repeated authentication failures without facing immediate restrictions. As a result, they have a more favorable chance of eventually acquiring valid credentials, leading to unauthorized administrative access and the potential to manipulate network configurations or disrupt services.

Potential Impact of CVE-2026-16347

  1. Unauthorized Access: The most immediate risk is the potential for attackers to gain unauthorized control over networking devices. Successful exploitation could allow an attacker to modify settings, monitor traffic, or execute malicious commands.

  2. Service Disruption: With administrative access obtained through this vulnerability, an attacker could disrupt normal operations of the network, leading to downtime and loss of service for users. This could have significant financial and reputational repercussions for organizations.

  3. Increased Attack Surface: By allowing repeated login attempts without meaningful safeguards, this vulnerability increases the attack surface of affected systems. It may lead to further exploitations, as attackers can leverage the compromised devices to infiltrate additional components of the network or facilitate other malicious activities.

Affected Version(s)

Cloud Hosted Router All versions

RouterOS All versions

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andre Santos of UniĂŁo Geek reported this vulnerability to CISA.
.