SSH session privilege manipulation via a crafted username in Mikrotik RouterOS

What is CVE-2026-86060?

CVE-2026-86060 is a vulnerability classified as Improper Neutralization of Argument Delimiters in a Command ('Argument Injection'), affecting RouterOS (affected versions: 7.24 – < 7.24.2, 7.0.0 – < 7.23.4, and other affected versions). This vulnerability is rated Critical, with a CVSS score of 9.2. This vulnerability has been observed being exploited in the wild.

Verify to continue the analysis

A short verification protects the vulnerability source and prevents automated AI abuse.

Overview

Original source data

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

Affected products and scope

CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.

Technical details

CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.

Exploitability

CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.

Technical impact

CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.

Business impact

CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.

Remediation

CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.

Detection

CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.
Sources (6)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan
CyStack VulnScan dashboard