RouterOS API Insufficient Session Exp Exp (CVE-2026-14227)
CVE-2026-14227 Published on July 30, 2026
Insufficient session expiration in MikroTik RouterOS
An API sessionmanagement flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Session Expiration vulnerability. This could allow active sessions to retain their previous permission set after inactivity timeouts or usergroup changes. As a result, an authenticated user whose permissions have been reduced may continue accessing information.
Vulnerability Analysis
CVE-2026-14227 can be exploited with network access, and requires user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
Products Associated with CVE-2026-14227
Want to know whenever a new CVE is published for MikroTik Routeros? stack.watch will email you.