← back
CVE-2026-67276criticalCWE-347

SSH user impersonation possible in Mikrotik RouterOS

50Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 9.2epss 0.2%
from disclosure to weapon1 days
Published on NVDSep 5
1st PoC+1d
exploitation probability
0.2%top 84% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Mikrotik · RouterOS
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.