CVE-2026-56719 | MikroTik RouterOS up to 6.49.18/7.11.2/7.23.x SessionSetupAndX uniPwdLen out-of-bounds
A vulnerability labeled as critical has been found in MikroTik RouterOS up to 6.49.18/7.11.2/7.23.x. Affected by this issue is some unknown functionality of the component SessionSetupAndX Handler. The manipulation of the argument uniPwdLen results in out-of-bounds read.
This vulnerability is reported as CVE-2026-56719. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.VulDB Recent EntriesRead More