A path traversal vulnerability has been identified in the RouterOS container feature. When importing a container image, specially crafted links inside the image could cause files to be written or deleted outside of the container’s own directory, anywhere on the router’s storage. The container does not need to be started for this to happen, importing the image is enough. The issue has been assigned CVE-2026-89021.
Who is affected: Only devices that use the container feature. The container package is not installed by default, and the feature has to be explicitly enabled by the administrator. If you do not use containers, you are not affected. RouterOS 6 does not have the container feature and is not affected.
Who can trigger it: A user with the rights to add containers on the router. The risk comes from container images obtained from untrusted sources, so this is especially relevant if you pull images from public registries.
This issue is fixed in RouterOS 7.24.2 (stable) and later releases.
Note for long-term users: this fix is not included in the 7.23.x long-term branch and there is no backport planned. If you use containers on a long-term release, upgrade to the stable branch (7.24.2 or later), or only import container images that you build yourself or obtain from a trusted source.
MikroTik always recommends keeping RouterOS devices up to date, only running container images from sources you trust, and using a strong firewall to limit exposure from untrusted networks.
Contact us about vulnerabilities