CVE-2026-14227
Received Received - Intake

Insufficient Session Expiration in MikroTik RouterOS API

Vulnerability report for CVE-2026-14227, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-30

Assigner: ICS-CERT

Description

An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Session Expiration vulnerability. This could allow active sessions to retain their previous permission set after inactivity timeouts or user‑group changes. As a result, an authenticated user whose permissions have been reduced may continue accessing information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-30
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mikrotik routeros *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-613 According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an Insufficient Session Expiration vulnerability in MikroTik RouterOS API. Active sessions keep their original permissions even after inactivity timeouts or user-group changes. This means a user whose access should be reduced can still access sensitive information.

Detection Guidance

Detecting this vulnerability requires checking for active API sessions in MikroTik RouterOS that persist after permission changes or inactivity timeouts. Review RouterOS logs for unusual session activity and verify session expiration settings. No specific commands are provided in the context.

Impact Analysis

If you use MikroTik RouterOS with API enabled, an attacker with reduced privileges could maintain unauthorized access to sensitive data or system functions. This could lead to data breaches or unauthorized network changes.

Compliance Impact

This vulnerability could violate compliance requirements that mandate proper session termination and access control, such as GDPR's data protection principles or HIPAA's access management rules. Unauthorized persistent access risks non-compliance.

Mitigation Strategies

Disable the MikroTik RouterOS API if not required. If enabled, ensure session expiration is properly configured and monitor active sessions for unauthorized access. Apply patches or updates from MikroTik if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14227. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart