Vulnerability Description
MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a crafted container image with symlinks pointing to arbitrary paths. Attackers can exploit unsanitized tar member path extraction during container import via /container/add to achieve root-privileged file creation, directory creation, file deletion via overlayfs whiteout, and hardlink creation on the persistent data partition without ever starting the container. The 7.23.x long-term branch does not contain this fix; the container binaries in container-7.23.3.npk and container-7.23.4.npk are byte-identical, and there is no fixed long-term release at the time of publication.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800
- https://www.vulncheck.com/advisories/mikrotik-routeros-path-traversal-via-contai
FAQ
What is CVE-2026-89021?
CVE-2026-89021 is a vulnerability with a CVSS score of 6.9 (MEDIUM). MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a...
How severe is CVE-2026-89021?
CVE-2026-89021 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-89021?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.