Successful exploitation of this vulnerability could allow an attacker to extract the router's WireGuard private key in plaintext using only low‑privilege API access, enabling full VPN impersonation and decryption of all associated traffic.
The following versions of MikroTik RouterOS are affected:
RouterOS vers:all/* (CVE-2026-14227)
Vendor
Equipment
MikroTik
MikroTik RouterOS
Insufficient Session Expiration
Critical Infrastructure Sectors: Information Technology
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Latvia
An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Session Expiration vulnerability. This could allow active sessions to retain their previous permission set after inactivity timeouts or user‑group changes. As a result, an authenticated user whose permissions have been reduced may...
Read the full advisory on CISA →