← back
CVE-2026-86060criticalunder attackCWE-88

SSH session privilege manipulation via a crafted username in Mikrotik RouterOS

78Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 9.2epss 0.4%
from disclosure to weapon
Published on NVDSep 5
CISA KEV+5d
exploitation probability
0.4%top 66% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
In short

A flaw in Mikrotik RouterOS SSH login allows attackers to use specially crafted usernames to bypass security policies and gain unauthorized administrative privileges. An attacker can exploit this remotely without needing valid credentials, making it a serious threat to router security.

Technical detail

CVE-2026-86060 is an argument-handling vulnerability (CWE-88) in RouterOS SSH authentication that permits manipulation of the policy mask through malformed usernames containing prohibited characters. An unauthenticated attacker can reach the SSH login helper and escalate privileges by circumventing the trusted policy enforcement mechanism; the attack requires network access to the SSH service but no prior authentication.

Summary generated and translated by AI from the official description.
RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Mikrotik · RouterOS
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.