CVE-2026-89021

medium

Description

MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a crafted container image with symlinks pointing to arbitrary paths. Attackers can exploit unsanitized tar member path extraction during container import via /container/add to achieve root-privileged file creation, directory creation, file deletion via overlayfs whiteout, and hardlink creation on the persistent data partition without ever starting the container. The 7.23.x long-term branch does not contain this fix; the container binaries in container-7.23.3.npk and container-7.23.4.npk are byte-identical, and there is no fixed long-term release at the time of publication.

References

https://www.vulncheck.com/advisories/mikrotik-routeros-path-traversal-via-container-oci-tar-image-extraction

https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800

Details

Source: Mitre, NVD

Published: 2026-09-14

Updated: 2026-09-16

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:L/Au:M/C:N/I:C/A:P

Severity: Medium

CVSS v3

Base Score: 6.9

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:L

Severity: Medium

CVSS v4

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:H/SA:L

Severity: Medium

EPSS

EPSS: 0.00244