CVE-2026-16347
published 2026-07-28CVE-2026-16347: MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not…
PriorityP358high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
0.39%
30.7th percentile
MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful rate-limiting, account lockout, or source-based restrictions, allowing repeated authentication failures to proceed without defensive response. In some versions, a fixed per-connection delay is present, but it can be bypassed through concurrent sessions, resulting in continued high-volume attempts. This deficiency increases the risk that an attacker could eventually obtain valid credentials and gain unauthorized access to administrative services.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mikrotik | cloud_hosted_router | — | — |
| mikrotik | routeros | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts.
ghsa_unreviewed·2026-07-28
CVE-2026-16347 [HIGH] CWE-307 MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts.
MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful rate-limiting, account lockout, or source-based restrictions, allowing repeated authentication failures to proceed without defensive response. In some versions, a fixed per-connection delay is present, but it can be bypassed through concurrent sessions, resulting in continued high-volume attempts. This deficiency increases the risk that an attacker could eventually obtain valid credentials and gain unauthorized access to administrative services.
VulDB
MikroTik RouterOS/Cloud Hosted Router excessive authentication
vuldb·2026-07-28·CVSS 8.8
CVE-2026-16347 [HIGH] MikroTik RouterOS/Cloud Hosted Router excessive authentication
A vulnerability described as problematic has been identified in MikroTik RouterOS and Cloud Hosted Router. This affects an unknown part. Such manipulation leads to improper restriction of excessive authentication attempts.
This vulnerability is referenced as CVE-2026-16347. It is possible to launch the attack remotely. No exploit is available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-28
Published