CVE-2026-67281
Received Received - Intake

Unauthenticated File Read in RouterOS WebFig

Vulnerability report for CVE-2026-67281, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-05

Last updated on: 2026-09-05

Assigner: CERT.PL

Description

RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving path dereferences this pointer with sufficient rights, then supply parent-directory components in an encrypted URI to escape the WebFig file namespace and disclose root-owned files, including configuration stores containing credentials.This issue was fixed in versions:Β 6.49.21 (Long-term),Β 7.23.4 (Long-term)Β andΒ 7.24.2 (Stable)

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-05
Last Modified
2026-09-05
Generated
2026-09-06
AI Q&A
2026-09-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
mikrotik routeros to 6.49.21 (inc)
mikrotik routeros to 7.23.4 (inc)
mikrotik routeros to 7.24.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CWE-824 The product accesses or uses a pointer that has not been initialized.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

RouterOS WebFig has an unauthenticated file-read vulnerability in the /jsproxy path. A stale uninitialized principal pointer in a session allows an attacker to bypass file authorization. By manipulating memory allocation and using encrypted URIs with parent-directory components, an attacker can access root-owned files, including configuration files containing credentials.

Detection Guidance

This vulnerability can be detected by checking RouterOS WebFig versions. If your system is running RouterOS versions prior to 6.49.21 (Long-term), 7.23.4 (Long-term), or 7.24.2 (Stable), it is vulnerable. No specific commands are provided in the context to exploit or detect this issue.

Impact Analysis

An unauthenticated attacker could read sensitive files on affected MikroTik routers, including configuration files with credentials. This could lead to unauthorized access, data breaches, or further network compromise. The vulnerability allows full file system access without authentication.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR (data protection) and HIPAA (health information privacy). Organizations using affected MikroTik devices may face compliance violations, legal penalties, and reputational damage due to potential data exposure.

Mitigation Strategies

Upgrade RouterOS to a fixed version: 6.49.21 (Long-term), 7.23.4 (Long-term), or 7.24.2 (Stable). Disable WebFig access if not required or restrict network access to the management interface.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67281. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart