SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-14227

MEDIUM · CVSS 4.9 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

Products utilizing MikroTik RouterOS with the API enabled are vulnerable due to an insufficient session expiration flaw, which allows active sessions to retain outdated permissions even after inactivity or user-group changes. This can lead to unauthorized access for users whose permissions have been downgraded, potentially exposing sensitive information. Organizations using MikroTik RouterOS should prioritize addressing this vulnerability to mitigate risks associated with unauthorized access.

CVE
CVE-2026-14227
Severity
MEDIUM
CVSS
4.9
EPSS
0.28%

Original NVD Description

An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Session Expiration vulnerability. This could allow active sessions to retain their previous permission set after inactivity timeouts or user‑group changes. As a result, an authenticated user whose permissions have been reduced may continue accessing information.