VORANT. Threat Intelligence Sign in Get the full feed

MikroTik RouterOS API session flaw exposes WireGuard keys

medium vulnerability technology

A session-expiration bug in MikroTik RouterOS lets low-privilege API users retain stale permissions, potentially exposing WireGuard private keys.

CISA published an ICS advisory for CVE-2026-14227, an insufficient session expiration flaw (CWE-613) affecting all versions of MikroTik RouterOS with the API enabled. The issue arises when a user's permissions are downgraded or their session times out, but the API session does not properly re-validate the new permission set, allowing continued access at the prior privilege level. According to the advisory summary, this could be leveraged to extract a router's WireGuard private key in plaintext using only low-privilege API access, which would enable full VPN impersonation and decryption of associated traffic.

MikroTik RouterOS is deployed worldwide across the Information Technology critical infrastructure sector, and the vendor is headquartered in Latvia. MikroTik's recommended mitigation is to ensure users are fully logged out when their permissions are reduced, so the new access policy takes effect immediately rather than persisting the old session state. CISA notes no known public exploitation of this vulnerability has been reported at this time, and the standard network-hardening guidance (isolating control system networks, restricting internet exposure, and using updated VPNs) applies.

The vulnerability was responsibly disclosed to CISA by researcher Andre Santos. Given the lack of a CVSS score in the advisory text and the absence of confirmed in-the-wild exploitation, this should be treated as a proof-of-concept-stage risk that organizations running RouterOS with API access enabled should prioritize patching or mitigating, particularly given the sensitivity of exposed VPN key material.

Mentioned in this report

Vulnerabilities CVE-2026-14227

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-01

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free