Description
MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a crafted container image with symlinks pointing to arbitrary paths. Attackers can exploit unsanitized tar member path extraction during container import via /container/add to achieve root-privileged file creation, directory creation, file deletion via overlayfs whiteout, and hardlink creation on the persistent data partition without ever starting the container. The 7.23.x long-term branch does not contain this fix; the container binaries in container-7.23.3.npk and container-7.23.4.npk are byte-identical. The vendor has confirmed that the issue is not resolved in the long-term release and that the fix is carried forward only in the stable branch from 7.24.2 onward, with no backport to the long-term branch planned.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Root-privileged file system modification
Action: Immediate Patch
AI Analysis

Impact

MikroTik RouterOS before 7.24.2 contains a path traversal flaw in the container package OCI/tar image extraction that allows attackers to write, delete, or hard‑link files outside the container root. By supplying a crafted image containing symlinks that point to arbitrary paths, the unsanitized tar extraction during the /container/add operation can create or remove files on the persistent data partition while running with root privileges, without ever launching the container. This vulnerability can also delete files through overlayfs whiteout and create hard links, giving an attacker powerful control over the device’s filesystem. The flaw affects all RouterOS builds that include the unpatched container binaries, including the 7.23.x long‑term branch where container‑7.23.3.npk and container‑7.23.4.npk remain vulnerable.

Affected Systems

All MikroTik RouterOS firmware builds before 7.24.2 are affected, including the 7.23.x long‑term branch. The container binaries in container-7.23.3.npk and container-7.23.4.npk are byte‑identical and remain vulnerable, and there is no patched long‑term release available at the time of the advisory.

Risk and Exploitability

The vulnerability has a CVSS score of 6.9, indicating moderate severity. EPSS score is <1%, and it is not listed in the CISA KEV catalog. The path traversal flaw is triggered when a container image is imported via the /container/add API, and it allows an attacker who can upload a crafted image to write files, delete files, or create hard links on the RouterOS persistent data partition. These capabilities can compromise the device’s filesystem integrity and availability, potentially disabling critical system functions if the device is not properly protected from unauthorized container uploads. The risk is higher if the /container/add API is exposed without adequate access controls.

Generated by OpenCVE AI on September 22, 2026 at 18:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade RouterOS firmware to version 7.24.2 or later.
  • Block or restrict access to the /container/add API endpoint to prevent the upload of container images.
  • Replace the vulnerable container packages (container‑7.23.3.npk and container‑7.23.4.npk) with a patched version or disable container functionality if not needed.

Generated by OpenCVE AI on September 22, 2026 at 18:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*

Tue, 22 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a crafted container image with symlinks pointing to arbitrary paths. Attackers can exploit unsanitized tar member path extraction during container import via /container/add to achieve root-privileged file creation, directory creation, file deletion via overlayfs whiteout, and hardlink creation on the persistent data partition without ever starting the container. The 7.23.x long-term branch does not contain this fix; the container binaries in container-7.23.3.npk and container-7.23.4.npk are byte-identical, and there is no fixed long-term release at the time of publication. MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a crafted container image with symlinks pointing to arbitrary paths. Attackers can exploit unsanitized tar member path extraction during container import via /container/add to achieve root-privileged file creation, directory creation, file deletion via overlayfs whiteout, and hardlink creation on the persistent data partition without ever starting the container. The 7.23.x long-term branch does not contain this fix; the container binaries in container-7.23.3.npk and container-7.23.4.npk are byte-identical. The vendor has confirmed that the issue is not resolved in the long-term release and that the fix is carried forward only in the stable branch from 7.24.2 onward, with no backport to the long-term branch planned.

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
References

Wed, 16 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
References

Tue, 15 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
First Time appeared Mikrotik
Mikrotik routeros
Vendors & Products Mikrotik
Mikrotik routeros

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a crafted container image with symlinks pointing to arbitrary paths. Attackers can exploit unsanitized tar member path extraction during container import via /container/add to achieve root-privileged file creation, directory creation, file deletion via overlayfs whiteout, and hardlink creation on the persistent data partition without ever starting the container. The 7.23.x long-term branch does not contain this fix; the container binaries in container-7.23.3.npk and container-7.23.4.npk are byte-identical, and there is no fixed long-term release at the time of publication.
Title MikroTik RouterOS Path Traversal via Container OCI/tar Image Extraction
Weaknesses CWE-22
CWE-59
References
Metrics cvssV3_1

{'score': 6.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:H/SA:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Mikrotik Routeros
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T15:21:49.680Z

Reserved: 2026-09-10T16:23:54.471Z

Link: CVE-2026-89021

cve-icon Vulnrichment

Updated: 2026-09-14T19:01:45.650Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T19:17:54.723

Modified: 2026-09-24T21:04:40.340

Link: CVE-2026-89021

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T19:00:13Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')