MikroTik RouterOS 7.9 < 7.23.4 / 7.24.x < 7.24.2 SSH Authentication Bypass (CVE-2026-67276)

high Nessus Plugin ID 344589

Synopsis

The remote networking device is affected by an authentication bypass vulnerability.

Description

According to its self-reported version, the remote networking device is running a version of MikroTik RouterOS 7.9 prior to 7.23.4, or 7.24.x prior to 7.24.2. It is, therefore, affected by an authentication bypass vulnerability.

RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key. (CVE-2026-67276)

Note that Nessus has not tested for this issue but has instead relied only on the router's self-reported version number.

Solution

Upgrade to MikroTik RouterOS 7.23.4, 7.24.2 or later.

See Also

https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve

https://mikrotik.com/supportsec/september-2026-vulnerability/

http://www.nessus.org/u?1fe530bb

Plugin Details

Severity: High

ID: 344589

File Name: mikrotik_CVE-2026-67276.nasl

Version: 1.1

Type: Remote

Family: Misc.

Published: 9/10/2026

Updated: 9/10/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 8.8

Percentile: 99.7

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS Score Source: CVE-2026-67276

CVSS v3

Risk Factor: High

Base Score: 8.1

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Vulnerability Information

CPE: cpe:/o:mikrotik:routeros

Required KB Items: MikroTik/RouterOS/Version

Patch Publication Date: 9/3/2026

Vulnerability Publication Date: 9/5/2026

Reference Information

CVE: CVE-2026-67276