Path Traversal Vulnerability in MikroTik RouterOS Affects File Security
CVE-2026-89021
What is CVE-2026-89021?
MikroTik RouterOS versions prior to 7.24.2 are vulnerable to a path traversal flaw in the OCI/tar image extraction process. This vulnerability allows attackers to manipulate the container image with crafted symlinks, enabling unauthorized file operations beyond the container's root directory. By exploiting this weakness during container importation, an attacker may achieve significant privileges, leading to potential root-privileged file and directory creation, deletion of files via overlay filesystem whiteout, and the ability to create hard links on the persistent data storage. Notably, the 7.23.x long-term branch remains unpatched, as the container binaries in the versions 7.23.3 and 7.23.4 are identical and lack a fixed long-term release.
Affected Version(s)
RouterOS 0 < 7.24.2
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
