[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-mikrotik-routeros-flaw-lets-stale-sessions-keep-old-permissions":10,"sections":35},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":30,"feedback":34,"feedback_at":22,"cost_usd":34,"total_tokens":34},4856,"mikrotik-routeros-flaw-lets-stale-sessions-keep-old-permissions","MikroTik RouterOS Flaw Lets Stale Sessions Keep Old Permissions","CISA's advisory opens with a VPN key-theft warning, but the actual bug just lets users keep stale permissions until logged out.","A newly disclosed MikroTik RouterOS bug means downgrading a user's permissions doesn't always take effect right away.\n\nCISA published the advisory on July 30, 2026, tracking it as CVE-2026-14227. The flaw sits in RouterOS's API session management. When an administrator lowers a user's permissions, or a session sits idle past its timeout, the active session can keep running under its old, broader access. MikroTik's fix isn't a patch; it's a process change. Admins are told to force a full logout whenever they downgrade someone so the new permission set actually applies. The issue affects every RouterOS version with the API enabled, which is effectively all of them, though CISA rates it medium severity (CVSS 4.9 to 6.9) with no known exploitation reported.\n\nThe advisory's own opening line is far more dramatic than the CVE it describes, warning that exploitation could let an attacker pull a router's WireGuard private key in plaintext and fully impersonate a VPN. Nothing in CVE-2026-14227's actual writeup, an insufficient session expiration flaw, supports that outcome. It's about stale permissions, not stolen keys. For a router platform used by ISPs, small businesses, and home networks worldwide, that gap between the headline claim and the technical detail matters for anyone trying to triage real risk.\n\nRouterOS runs on millions of devices with a well known habit of shipping defaults nobody hardens. The actual fix here is boring and correct: log people out the moment you take away their access.","[\"mikrotik\",\"routeros\",\"vulnerability\",\"cisa\"]","2026-07-30T12:00:00.000Z","2026-08-14T02:10:06.124Z","2026-08-14T02:10:17.944Z","published",null,[],"security",[26,27,28,29],"mikrotik","routeros","vulnerability","cisa",[31],{"name":32,"url":33},"CISA Advisories","https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Fics-advisories\u002Ficsa-26-211-01",0,{"sections":36},[37,42,45,50,55,60,65,70,75,80,85,90,95,100],{"name":38,"slug":39,"count":40,"latest_published_at":41},"AI","ai",3293,"2026-08-20T04:00:00.000Z",{"name":43,"slug":24,"count":44,"latest_published_at":41},"Security",435,{"name":46,"slug":47,"count":48,"latest_published_at":49},"Policy","policy",210,"2026-08-19T09:32:27.000Z",{"name":51,"slug":52,"count":53,"latest_published_at":54},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":56,"slug":57,"count":58,"latest_published_at":59},"Hardware","hardware",140,"2026-08-19T18:25:42.000Z",{"name":61,"slug":62,"count":63,"latest_published_at":64},"Consumer Tech","consumer-tech",95,"2026-08-18T16:05:00.000Z",{"name":66,"slug":67,"count":68,"latest_published_at":69},"Science","science",90,"2026-08-19T18:41:02.000Z",{"name":71,"slug":72,"count":73,"latest_published_at":74},"Software","software",73,"2026-08-18T07:51:50.000Z",{"name":76,"slug":77,"count":78,"latest_published_at":79},"Dev Tools","dev-tools",69,"2026-08-18T04:00:00.000Z",{"name":81,"slug":82,"count":83,"latest_published_at":84},"Startups","startups",47,"2026-08-19T19:13:46.000Z",{"name":86,"slug":87,"count":88,"latest_published_at":89},"Gaming","gaming",41,"2026-07-09T04:00:00.000Z",{"name":91,"slug":92,"count":93,"latest_published_at":94},"General","general",33,"2026-08-18T22:18:13.000Z",{"name":96,"slug":97,"count":98,"latest_published_at":99},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":101,"slug":102,"count":103,"latest_published_at":104},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]