MEDIUMVulnerability

CVE-2026-89021

MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a crafted container image with symlinks pointing to arbitrary paths. Attackers can exploit unsanitized tar member path extraction during container import via /container/add to achieve root-privileged file creation, directory creation, file deletion via overlayfs whiteout, and hardlink creation on the persistent data partition without ever starting the container. The 7.23.x long-term branch does not contain this fix; the container binaries in container-7.23.3.npk and container-7.23.4.npk are byte-identical. The vendor has confirmed that the issue is not resolved in the long-term release and that the fix is carried forward only in the stable branch from 7.24.2 onward, with no backport to the long-term branch planned.

Properties

severity
MEDIUM
score
6.9
cve_id
CVE-2026-89021
signal_observed_at
2026-09-23T22:45:07+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:L
published_at
2026-09-14T19:17:54.723
last_modified
2026-09-22T17:17:28.500

Related Entities (3)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (2)

[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
[Weakness]Improper Link Resolution Before File Access ('Link Following')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-89021 — Ninja Signal Threat Intelligence | Ninja Signal