CVE-2026-67276
Last modified
CVE-2026-67276 is a critical-severity vulnerability rated 9.2/10 on the CVSS scale. RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable). EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Mikrotik | RouterOS | >= 7.24, < 7.24.2; >= 7.9, < 7.23.4 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-67276?
How severe is CVE-2026-67276?
How do I fix CVE-2026-67276?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-67266Dell Command Update (DCU), versions prior to 5.7.1, contain …5.5
- CVE-2026-67267Dell Command Update (DCU), versions prior to 5.7.1, contain …5.5
- CVE-2026-67268Dell Command Update (DCU), versions prior to 5.7.1, contain …6.5
- CVE-2026-6727A timing side-channel vulnerability exists in the RSA OAEP d…5.9
- CVE-2026-67271Dell PowerStore SDNAS, contains an Out-of-bounds Write vulne…9.8
- CVE-2026-67275Dell PowerProtect One, versions 20.1.0.0 and below, contain …6.5
- CVE-2026-67277RouterOS accepts a "related" btest connection before the cor…8.8
- CVE-2026-67278MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatur…6.3
- CVE-2026-67279RouterOS SSH enters the connection protocol after a client-r…6.9
- CVE-2026-6728The Slider Revolution plugin for WordPress is vulnerable to …5.3
- CVE-2026-67281RouterOS WebFig contains an unauthenticated file-read vulner…8.7
- CVE-2026-67282Joomla Extension - fabrikar.com - Unauthenticated remote cod…10
Are you affected by CVE-2026-67276?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
