Search/CVE-2026-67281
CVE

CVE-2026-67281

RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving path dereferences this pointer with sufficient rights, then supply parent-directory components in an encrypted URI to escape the WebFig file namespace and disclose root-owned files, including configuration stores containing credentials.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)

CVSS v3.1
EPSS
0.45%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
EPSS Trend
Sep 7, 2026Sep 9, 2026
0.01pp
0.46% → 0.45% over 2 tracked changes
Connections
2 relationships
Timeline
disclosure → media coverage
Sep 5, 2026
Disclosure — published as a CVE record.