MikroTik RouterOS 7.9 < 7.23.4 / 7.24.x < 7.24.2 SSH Authentication Bypass (CVE-2026-67276)

critical Nessus Plugin ID 344589

Synopsis

The remote networking device is affected by an authentication bypass vulnerability.

Description

According to its self-reported version, the remote networking device is running a version of MikroTik RouterOS 7.9 prior to 7.23.4, or 7.24.x prior to 7.24.2. It is, therefore, affected by an authentication bypass vulnerability.

RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key. (CVE-2026-67276)

Note that Nessus has not tested for this issue but has instead relied only on the router's self-reported version number.

Solution

Upgrade to MikroTik RouterOS 7.23.4, 7.24.2 or later.

See Also

https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve

https://mikrotik.com/supportsec/september-2026-vulnerability/

http://www.nessus.org/u?1fe530bb

Plugin Details

Severity: Critical

ID: 344589

File Name: mikrotik_CVE-2026-67276.nasl

Version: 1.4

Type: Remote

Family: Misc.

Published: 9/10/2026

Updated: 9/28/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.4

Percentile: 99.82

CVSS v2

Risk Factor: High

Base Score: 7.6

Temporal Score: 6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-67276

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.3

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: Critical

Base Score: 9.2

Threat Score: 8.2

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

CPE: cpe:/o:mikrotik:routeros

Required KB Items: MikroTik/RouterOS/Version

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/3/2026

Vulnerability Publication Date: 9/5/2026

Reference Information

CVE: CVE-2026-67276

IAVA: 2026-A-0941