Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-86060— SSH session privilege manipulation via a crafted username in Mikrotik RouterOS

Quick assessment

Affected
Mikrotik RouterOS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

RouterOS 在 SSH 登录路径中存在一个参数处理缺陷。当使用以禁止字符开头的用户名时,攻击者可以修改受信任的 RouterOS 策略掩码(policy mask),从而导致权限提升。利用此漏洞需要一个未认证的 SSH 会话以触达 RouterOS 登录辅助程序。该问题已在以下版本中修复:6.49.21(Lont-term)、7.23.4(Lont-term)和 7.24.2(Stable)。

CVSS 9.2 · Critical EPSS 0.40% · P33

Affected Version Matrix 3

VendorProduct Version RangeStatus
Mikrotik RouterOS 7.24< 7.24.2 affected
7.0.0< 7.23.4 affected
6.0.0< 6.49.21 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-86060

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SSH session privilege manipulation via a crafted username in Mikrotik RouterOS
Source: CVE Program / CVE List V5
Vulnerability Description
RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
参数注入或修改
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Mikrotik RouterOS 7.24 ~ 7.24.2 -

II. Public POCs for CVE-2026-86060

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-86060

登录查看更多情报信息。

Security Blog Posts for CVE-2026-86060 (3)

Vendor Pages for CVE-2026-86060 (4)

Same Patch Batch · Mikrotik · 2026-09-05 · 6 CVEs total

CVE-2026-67276 9.2 CRITICAL SSH user impersonation possible in Mikrotik RouterOS
CVE-2026-67277 8.8 HIGH Kernel memory disclosure and denial of service in MikroTik RouterOS btest service
CVE-2026-67281 8.7 HIGH Unauthenticated file read in Mikrotik RouterOS
CVE-2026-67279 6.9 MEDIUM SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS
CVE-2026-67278 6.3 MEDIUM TLS server impersonation possible in Mikrotik RouterOS

IV. Related Vulnerabilities

V. Comments for CVE-2026-86060

No comments yet


Leave a comment