MikroTik RouterOS API lacks ratelimiting, enabling bruteforce attacks
CVE-2026-16347 Published on July 28, 2026
Improper restriction of excessive authentication attempts in MikroTik RouterOS and Cloud Hosted Router
MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful rate-limiting, account lockout, or source-based restrictions, allowing repeated authentication failures to proceed without defensive response. In some versions, a fixed per-connection delay is present, but it can be bypassed through concurrent sessions, resulting in continued high-volume attempts. This deficiency increases the risk that an attacker could eventually obtain valid credentials and gain unauthorized access to administrative services.
Vulnerability Analysis
Weakness Type
Improper Restriction of Excessive Authentication Attempts
The software does not implement sufficient measures to prevent multiple failed authentication attempts within in a short time frame, making it more susceptible to brute force attacks.
Products Associated with CVE-2026-16347
Want to know whenever a new CVE is published for MikroTik Routeros? stack.watch will email you.
Affected Versions
MikroTik RouterOS:- Version All versions is affected.
- Version All versions is affected.