---
cve: "CVE-2026-86060"
severity: "LOW"
cvss: 3.1
epss: "5.3%"
vendor: "Generic Security"
kev: false
exploited: false
published: "2026-09-05 20:17:18"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-06T10:27:01+02:00"
---

# CVE-2026-86060

> 3.1 LOW

## Beschreibung

RouterOS contains an argument-handling flaw in the SSH login
path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

## Referenzen

- <https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve>
- <https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/>
- <https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802>
- <https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801>
- <https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800>
- <https://mikrotik.com/supportsec/september-2026-vulnerability/>
- <https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-86060) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
