What is CVE-2026-14227?
An Insufficient Session Expiration vulnerability exists in products with the MikroTik RouterOS API enabled. This flaw may allow active sessions to retain their previous permissions after inactivity timeouts or user-group changes. It is recommended to apply security updates on devices using the RouterOS API.
Azərbaycanca: MikroTik RouterOS API-nin aktiv olduğu məhsullarda "Qeyri-kafi Sessiya Müddəti" zəifliyi aşkarlanıb. Bu qüsur, istifadəçi qrupu dəyişikliyi və ya qeyri-aktivlik müddətindən sonra aktiv sessiyaların əvvəlki icazələrini saxlamasına səbəb ola bilər. RouterOS API-dən istifadə edən qurğularda təhlükəsizlik yeniləmələrini tətbiq etmək tövsiyə olunur.
FAQ2
What risk can the session expiration vulnerability in RouterOS API pose after a user-group change?
Due to CVE-2026-14227, active sessions may retain their previous permissions after a user-group change.
What measure should be taken to protect against this flaw in MikroTik?
It is recommended to apply security updates on devices using the RouterOS API.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.