MikroTik RouterOS Improper Verification of Cryptographic Signature (CVE-2026-67276)

high Tenable OT Security Plugin ID 506060

Synopsis

The remote OT asset is affected by a vulnerability.

Description

RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Refer to the vendor advisory.

See Also

https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve

https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801

https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800

https://mikrotik.com/supportsec/september-2026-vulnerability/

http://www.nessus.org/u?1fe530bb

http://www.nessus.org/u?eed3942f

Plugin Details

Severity: High

ID: 506060

File Name: tenable_ot_mikrotik_CVE-2026-67276.nasl

Version: 1.1

Type: Remote

Family: Tenable.ot

Published: 10/5/2026

Updated: 10/5/2026

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Critical

Score: 9.4

Percentile: 99.82

CVSS v3

Risk Factor: High

Base Score: 8.1

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/o:mikrotik:routeros:7

Required KB Items: Tenable.ot/MikroTik

Patch Publication Date: 9/5/2026

Vulnerability Publication Date: 9/5/2026

Reference Information

CVE: CVE-2026-67276

CWE: 347