RouterOS API Insufficient Session Exp Exp (CVE-2026-14227)
CVE-2026-14227 Published on July 30, 2026

Insufficient session expiration in MikroTik RouterOS
An API sessionmanagement flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Session Expiration vulnerability. This could allow active sessions to retain their previous permission set after inactivity timeouts or usergroup changes. As a result, an authenticated user whose permissions have been reduced may continue accessing information.

NVD

Vulnerability Analysis

CVE-2026-14227 can be exploited with network access, and requires user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
HIGH
User Interaction:
NONE

Weakness Type

Insufficient Session Expiration

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."


Products Associated with CVE-2026-14227

Want to know whenever a new CVE is published for MikroTik Routeros? stack.watch will email you.

 

Affected Versions

MikroTik RouterOS Version All versions is affected by CVE-2026-14227