A session-management flaw in MikroTik RouterOS's API allows authenticated users whose permissions have been downgraded to retain their prior access levels, since sessions are not properly invalidated after permission changes or inactivity timeouts. The advisory description also notes a more severe potential consequence: low-privilege API access could be leveraged to extract a router's WireGuard private key in plaintext, enabling full VPN impersonation and decryption of associated traffic. No public exploitation has been reported at this time.
Updated Aug 1, 2026 · CVSS 4.9