THREAT OPS › Threat News › [NVD] CVE-2026-67281 — RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving pat
[NVD] CVE-2026-67281 — RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving pat
CVE-2026-67281 CVSS: None Published: 2026-09-05T20:17:18.547
RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving path dereferences this pointer with sufficient rights, then
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-67281cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-67281