Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-89021— MikroTik RouterOS Path Traversal via Container OCI/tar Image Extraction

Quick assessment

Affected
MikroTik RouterOS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MikroTik RouterOS 7.24.2 之前的版本中存在一个路径遍历漏洞,位于容器包的 OCI/tar 镜像解压过程中。攻击者可以通过提供一个经过特制的容器镜像(其中包含指向任意路径的符号链接),从而在容器根目录之外写入文件。攻击者可以利用容器导入过程中未净化的 tar 成员路径解压(通过 /container/add 接口)来实现:以 root 权限创建文件、创建目录、通过 overlayfs 白出(whiteout)机制删除文件,以及在持久数据分区上创建硬链接——所有这些操作均无需实际启动容器即可完成

CVSS 6.9 · Medium

Possible ATT&CK Techniques 1 AI

T1076

Affected Version Matrix 1

VendorProduct Version RangeStatus
MikroTik RouterOS < 7.24.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-89021

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MikroTik RouterOS Path Traversal via Container OCI/tar Image Extraction
Source: CVE Program / CVE List V5
Vulnerability Description
MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a crafted container image with symlinks pointing to arbitrary paths. Attackers can exploit unsanitized tar member path extraction during container import via /container/add to achieve root-privileged file creation, directory creation, file deletion via overlayfs whiteout, and hardlink creation on the persistent data partition without ever starting the container. The 7.23.x long-term branch does not contain this fix; the container binaries in container-7.23.3.npk and container-7.23.4.npk are byte-identical, and there is no fixed long-term release at the time of publication.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
在文件访问前对链接解析不恰当(链接跟随)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MikroTik RouterOS 0 ~ 7.24.2 -

II. Public POCs for CVE-2026-89021

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-89021

登录查看更多情报信息。

Vendor Advisories for CVE-2026-89021 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-89021

No comments yet


Leave a comment