{"id":"CVE-2026-89021","title":"MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a crafted container image with symlink…","summary":"MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a crafted container image with symlink…","severity":"medium","cvss":6.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:L","cwe":["CWE-22","CWE-59"],"vendor":"MikroTik","product":"RouterOS","affected":["RouterOS < 7.24.2"],"published":"2026-09-14","updated":"2026-09-24","sourceUpdated":"2026-09-24T21:04:40.340","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-89021","references":[{"url":"https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/mikrotik-routeros-path-traversal-via-container-oci-tar-image-extraction","label":"disclosure@vulncheck.com"},{"url":"https://mikrotik.com/supportsec/september-2026-vulnerability","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"epss":0.00381,"epssPercentile":0.29277,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-14T19:01:29.158499Z"},"ingestedAt":"2026-09-14T19:13:23.482Z","slug":"CVE-2026-89021","body":"## Overview\n\nMikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a crafted container image with symlinks pointing to arbitrary paths. Attackers can exploit unsanitized tar member path extraction during container import via /container/add to achieve root-privileged file creation, directory creation, file deletion via overlayfs whiteout, and hardlink creation on the persistent data partition without ever starting the container. The 7.23.x long-term branch does not contain this fix; the container binaries in container-7.23.3.npk and container-7.23.4.npk are byte-identical. The vendor has confirmed that the issue is not resolved in the long-term release and that the fix is carried forward only in the stable branch from 7.24.2 onward, with no backport to the long-term branch planned.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":38,"depthScoreParts":{"impact":38,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}