CVE-2026-86060CWE-88

CVE-2026-86060

published September 6, 2026

CVSS
9.2
EPSS
0%
Percentile
33.4
In the wild
Unconfirmed
What it is

RouterOS contains an argument-handling flaw in the SSH login

path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

The record
Technical detail
CVSS
9.2 · NONE
CVSS v4.0
9.2 · CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00401 · 33.4th percentile
Weakness
CWE-88 · Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
Published
2026-09-06T00:17Z
References (7)
EPSS history
Timeline
  • 07 SEP 03:36Z
    EPSS moved — → 0%
    epss
  • 05 SEP 20:00Z
    SSH session privilege manipulation via a crafted username in Mikrotik RouterOS
    cvelistv5