Description
An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Session Expiration vulnerability. This could allow active sessions to retain their previous permission set after inactivity timeouts or user‑group changes. As a result, an authenticated user whose permissions have been reduced may continue accessing information.
Published: 2026-07-30
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An API session‑management flaw in MikroTik RouterOS allows active sessions to retain old permissions after the session times out or after a user’s group permissions are changed. The flaw falls under CWE‑613. Based on the description, it is inferred that an authenticated user with reduced privileges can still perform unauthorized actions, potentially exposing sensitive data.

Affected Systems

The vulnerability affects MikroTik RouterOS products that have the API enabled, across all currently supported versions. No specific product or version sub‑range is listed, so all installations that expose the API are potentially impacted.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium‑to‑high risk, while the EPSS score of < 1% suggests the likelihood of exploitation is low. The flaw is not listed in CISA’s KEV catalog. The likely attack vector is inferred to require authenticated access, either through the open API or local administrator privileges. Based on the description, it is inferred that the attacker would need to be already authenticated to exploit the flaw. Once a session survives a permission downgrade, the user could perform actions beyond their new authorization level. There are no publicly known exploits, so the risk is largely theoretical at this time.

Generated by OpenCVE AI on August 4, 2026 at 11:43 UTC.

Remediation

Vendor Solution

MikroTik recommends administrators to ensure that when a user’s permissions are downgraded, the affected user is fully logged out so the new policy can take effect. For more information, contact MikroTik (https://mikrotik.com/support).


OpenCVE Recommended Actions

  • Promptly log out or force‑disconnect all users whose permissions have been reduced to enforce the updated policy.
  • Upgrade MikroTik RouterOS to the latest stable release that addresses this session‑expiration issue.
  • Disable the MikroTik RouterOS API if it is not required for your environment.
  • Implement continuous monitoring of permission changes and active sessions to detect any residual sessions that should have expired.

Generated by OpenCVE AI on August 4, 2026 at 11:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Mikrotik
Mikrotik routeros
Vendors & Products Mikrotik
Mikrotik routeros
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Description An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Session Expiration vulnerability. This could allow active sessions to retain their previous permission set after inactivity timeouts or user‑group changes. As a result, an authenticated user whose permissions have been reduced may continue accessing information.
Title Insufficient session expiration in MikroTik RouterOS
Weaknesses CWE-613
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Mikrotik Routeros
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-30T19:15:52.381Z

Reserved: 2026-06-30T12:02:13.218Z

Link: CVE-2026-14227

cve-icon Vulnrichment

Updated: 2026-07-30T19:15:48.255Z

cve-icon NVD

Status : Received

Published: 2026-07-30T19:17:07.493

Modified: 2026-07-30T20:16:52.840

Link: CVE-2026-14227

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T11:45:03Z

Weaknesses
  • CWE-613

    Insufficient Session Expiration