{"id":"CVE-2026-67281","title":"RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization","summary":"RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare…","severity":"high","cvss":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-22","CWE-824"],"vendor":"Mikrotik","product":"RouterOS","affected":["RouterOS >= 7.24 < 7.24.2","RouterOS >= 7.20 < 7.23.4"],"published":"2026-09-05","updated":"2026-09-08","sourceUpdated":"2026-09-08T16:18:11.057","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-67281","references":[{"url":"https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve","label":"cvd@cert.pl"},{"url":"https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/","label":"cvd@cert.pl"},{"url":"https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801","label":"cvd@cert.pl"},{"url":"https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800","label":"cvd@cert.pl"},{"url":"https://mikrotik.com/supportsec/september-2026-vulnerability/","label":"cvd@cert.pl"},{"url":"https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/","label":"cvd@cert.pl"},{"url":"https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802","label":"cvd@cert.pl"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-08T15:31:52.946442Z"},"cvssSource":"cna","epss":0.0045,"epssPercentile":0.38373,"ingestedAt":"2026-09-06T13:55:47.630Z","slug":"CVE-2026-67281","body":"## Overview\n\nRouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving path dereferences this pointer with sufficient rights, then supply parent-directory components in an encrypted URI to escape the WebFig file namespace and disclose root-owned files, including configuration stores containing credentials.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":60,"depthScoreParts":{"impact":47.8,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":5427,"id":"CVE-2026-67281","ts":1788887281458,"field":"exploit_available","old":"false","new":"true"},{"seq":5426,"id":"CVE-2026-67281","ts":1788887281458,"field":"cvss","old":null,"new":"8.7"},{"seq":5425,"id":"CVE-2026-67281","ts":1788887281458,"field":"severity","old":"none","new":"high"},{"seq":4310,"id":"CVE-2026-67281","ts":1788886395309,"field":"exploit_available","old":"true","new":"false"},{"seq":4309,"id":"CVE-2026-67281","ts":1788886395309,"field":"cvss","old":"8.7","new":null},{"seq":4308,"id":"CVE-2026-67281","ts":1788886395309,"field":"severity","old":"high","new":"none"},{"seq":3282,"id":"CVE-2026-67281","ts":1788885294115,"field":"exploit_available","old":"false","new":"true"},{"seq":3281,"id":"CVE-2026-67281","ts":1788885294115,"field":"cvss","old":null,"new":"8.7"},{"seq":3280,"id":"CVE-2026-67281","ts":1788885294115,"field":"severity","old":"none","new":"high"}]}