MikroTik RouterOS Argument Injection (CVE-2026-86060)

critical Tenable OT Security Plugin ID 506058

Synopsis

The remote OT asset is affected by a vulnerability.

Description

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Refer to the vendor advisory.

See Also

https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve

https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802

https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801

https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800

https://mikrotik.com/supportsec/september-2026-vulnerability/

http://www.nessus.org/u?1fe530bb

http://www.nessus.org/u?eed3942f

http://www.nessus.org/u?f5c57ae1

Plugin Details

Severity: Critical

ID: 506058

File Name: tenable_ot_mikrotik_CVE-2026-86060.nasl

Version: 1.1

Type: Remote

Family: Tenable.ot

Published: 10/5/2026

Updated: 10/5/2026

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Critical

Score: 9.4

Percentile: 99.82

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/o:mikrotik:routeros:6, cpe:/o:mikrotik:routeros:7

Required KB Items: Tenable.ot/MikroTik

Patch Publication Date: 9/5/2026

Vulnerability Publication Date: 9/5/2026

Reference Information

CVE: CVE-2026-86060

CWE: 88