Executive brief
MikroTik RouterOS WebFig is a web interface for managing router devices. This vulnerability allows an attacker without authentication to read sensitive files on the device, including configuration data and credentials, by exploiting a memory management flaw in the file-serving path.
Technical details
CVE-2026-67281 is an access of uninitialized pointer (CWE-824) in RouterOS WebFig's /jsproxy path. An unauthenticated network attacker can exploit heap allocation timing to cause the file authorization logic to dereference a stale principal pointer with elevated privileges, then supply path traversal components in an encrypted URI to escape the WebFig namespace and read root-owned files.
Affected products
- MikroTik RouterOS 7.20 to 7.23.3, 7.24.0 to 7.24.1
Timeline
- 2026-09-05: disclosed
- 2026-09-05: patched: Fixed in RouterOS 7.23.4 (Long-term) and 7.24.2 (Stable)