{
  "schemaVersion": "guard-threat-campaign/v1",
  "id": "HGTC-2026-7E9381C6",
  "slug": "cve-2026-67276-mikrotik-routeros-mikrotrick-ssh-cluster",
  "title": "MikroTik RouterOS SSH key check allows user impersonation",
  "aliases": [
    "CVE-2026-67276",
    "MikroTrick"
  ],
  "summary": "RouterOS does not compare the complete RSA public key when matching SSH auth — checking key type and modulus but omitting the exponent. An attacker who knows an authorized RSA modulus can forge a valid signature and open an SSH command channel as the target user. Fixed in 7.24.2, 7.23.4, and 6.49.21.",
  "status": "published",
  "severity": "critical",
  "confidence": "high",
  "uncertainty": "Confirm your RouterOS train (6.x vs 7.x) before choosing the fixed build.",
  "firstObservedAt": "2026-09-05T20:00:55.811Z",
  "lastObservedAt": "2026-09-05T20:00:55.811Z",
  "publishedAt": "2026-09-20T19:29:52.642Z",
  "reviewedAt": "2026-09-20T19:29:47.941Z",
  "expiresAt": "2026-09-05T20:00:55.811Z",
  "reviewer": "HOL Guard Security Publishing",
  "sources": [
    {
      "id": "certpl",
      "label": "CERT.pl MikroTik RouterOS advisory",
      "url": "https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve",
      "sourceType": "government",
      "observedAt": "2026-09-05T20:00:55.811Z"
    },
    {
      "id": "nvd",
      "label": "NVD CVE-2026-67276",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67276",
      "sourceType": "vulnerability_database",
      "observedAt": "2026-09-05T20:00:55.811Z"
    },
    {
      "id": "hol-blog",
      "label": "HOL Guard operator write-up",
      "url": "https://hol.org/blog/cve-2026-67276-mikrotik-routeros-mikrotrick-ssh-cluster",
      "sourceType": "other_primary",
      "observedAt": "2026-09-05T20:00:55.811Z"
    }
  ],
  "artifacts": [
    {
      "id": "routeros",
      "artifactClass": "package",
      "ecosystem": "mikrotik",
      "name": "RouterOS",
      "version": ">=7.24 <7.24.2 || >=7.0.0 <7.23.4 || >=6.0.0 <6.49.21",
      "defanged": false
    }
  ],
  "indicators": [],
  "timeline": [
    {
      "id": "disclosure",
      "occurredAt": "2026-09-05T20:00:55.811Z",
      "eventType": "disclosure",
      "summary": "CVE-2026-67276 MikroTik RouterOS SSH RSA key matching flaw disclosed.",
      "sourceIds": [
        "certpl",
        "nvd"
      ]
    },
    {
      "id": "hol-publish",
      "occurredAt": "2026-09-05T21:00:00.000Z",
      "eventType": "other",
      "summary": "HOL Guard published operator blog coverage for CVE-2026-67276.",
      "sourceIds": [
        "hol-blog"
      ]
    }
  ],
  "coverage": [],
  "policies": [],
  "limitations": [
    "Requires SSH exposure and knowledge of an authorized RSA modulus.",
    "Fixed builds from pack: 7.24.2, 7.23.4, 6.49.21.",
    "HOL blog is operator guidance, not a substitute for CERT.pl / MikroTik."
  ],
  "correctionHref": "/guard/security/campaigns/cve-2026-67276-mikrotik-routeros-mikrotrick-ssh-cluster/corrections"
}
