Path Traversal Vulnerability in MikroTik RouterOS Affects File Security
CVE-2026-89021

6.9MEDIUM

Key Information:

Vendor

Mikrotik

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-89021?

MikroTik RouterOS versions prior to 7.24.2 are vulnerable to a path traversal flaw in the OCI/tar image extraction process. This vulnerability allows attackers to manipulate the container image with crafted symlinks, enabling unauthorized file operations beyond the container's root directory. By exploiting this weakness during container importation, an attacker may achieve significant privileges, leading to potential root-privileged file and directory creation, deletion of files via overlay filesystem whiteout, and the ability to create hard links on the persistent data storage. Notably, the 7.23.x long-term branch remains unpatched, as the container binaries in the versions 7.23.3 and 7.23.4 are identical and lack a fixed long-term release.

Affected Version(s)

RouterOS 0 < 7.24.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kazuma Matsumoto, Security Researcher
.