SSH session privilege manipulation via a crafted username in Mikrotik RouterOS
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
A flaw in Mikrotik RouterOS SSH login allows attackers to use specially crafted usernames to bypass security policies and gain unauthorized administrative privileges. An attacker can exploit this remotely without needing valid credentials, making it a serious threat to router security.
CVE-2026-86060 is an argument-handling vulnerability (CWE-88) in RouterOS SSH authentication that permits manipulation of the policy mask through malformed usernames containing prohibited characters. An unauthenticated attacker can reach the SSH login helper and escalate privileges by circumventing the trusted policy enforcement mechanism; the attack requires network access to the SSH service but no prior authentication.