RouterOS SSH Rekey Escalation Enables Unauthenticated Exec in 6.x/7.x
CVE-2026-67279 Published on September 5, 2026
SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS
RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
Vulnerability Analysis
CVE-2026-67279 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
Improper Enforcement of Behavioral Workflow
The software supports a session in which more than one behavior must be performed by an actor, but it does not properly ensure that the actor performs the behaviors in the required sequence.
Products Associated with CVE-2026-67279
Want to know whenever a new CVE is published for MikroTik Routeros? stack.watch will email you.
Affected Versions
Mikrotik RouterOS:- Version 7.24 and below 7.24.2 is affected.
- Version 7.0.0 and below 7.23.4 is affected.
- Version 6.0.0 and below 6.49.21 is affected.