Vulnerability Intelligence Report
SSH session privilege manipulation via a crafted username in Mikrotik RouterOS
CVE-2026-86060
RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
CISA KEV
SSVC: Active Exploitation
Automatable
CVSS Base Score
9.2
CRITICAL
EPSS Probability:0.40%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-88 ↗CWE-88 Improper neutralization of argument delimiters in a command ('argument injection')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Mikrotik | RouterOS | 7.24 < 7.24.2 (affected), 7.0.0 < 7.23.4 (affected), 6.0.0 < 6.49.21 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | CERT.PL · CERT · Poland |
| Reserved | 2026-09-04T19:32:24 |
| Published | 2026-09-05T20:00:59 |
| Last Updated | 2026-09-11T03:55:59 |
Community Chatter & Buzz