SSH Rekey During Authentication: The Protocol Edge Case Behind CVE-2026-67279
Vulnerability overview
CVE-2026-67279 is, at its core, a protocol bookkeeping error. MikroTik's RouterOS SSH server failed to resume authentication after a rekey performed during the authentication phase, and moved instead into the channel phase. The defect was fixed in the September 2026 RouterOS releases and forms the first half of the MikroTrick chain described by CERT Polska.
Mechanism and exploitation conditions
SSH separates into three consecutive layers, described by RFC 4253, RFC 4252 and RFC 4254: transport, user authentication, and connection with its channels. After the initial key exchange the two sides derive session keys and the transport layer protects subsequent data. Either side may then trigger a rekey to replace those keys without dropping the TCP connection and without disturbing higher-layer protocol state.
Rekey is normally driven by data volume or elapsed time, which places it after authentication in typical sessions. The specification does not forbid a rekey earlier. That is the edge case. The vulnerable server accepted an authentication-phase rekey and, when it completed, left its temporary rekey state for the channel phase. The interrupted authentication was never resumed, yet channel requests were honoured.
The result is a session that reaches the connection layer while the authentication layer is unfinished. From the client side this is indistinguishable from a server that skipped a step; from the server side it is a missing state transition. Exploitation requires SSH reachability and the ability to complete a key exchange and request a rekey. There is no credential step to defeat because none is reached.
Impact
Alone, the flaw yields a channel without rights - not a shell, not an identity. Its significance is structural: the channel phase is the precondition the login argument-injection flaw needs to deliver an attacker-chosen policy mask. Chained, the two defects produce a full administrative console. For defenders the lesson generalises beyond this CVE, because state-machine shortcuts in protocol implementations are a recurring failure mode that rarely appears in a scanner's signature set.
Affected products and scope
The fix shipped in RouterOS 7.25beta3, 7.24.2, 7.23.4 and 6.49.21. CERT Polska's material notes that some publications incorrectly attributed a separate RSA-key impersonation issue, CVE-2026-67276, to the MikroTrick chain; that defect requires knowledge of an account name and its public-key module and yields access only to that account, making it far harder to use at scale.
ZoomEye measurement for this topic used os="RouterOS" && service="ssh" and returned 9,559 devices, describing RouterOS SSH reachability rather than confirmed vulnerability.
Remediation and mitigations
- Update RouterOS to a fixed build on all maintained branches.
- Treat state-machine vulnerabilities as requiring patch verification rather than scanner clearance.
- Restrict SSH management reachability to administrative networks or VPN paths.
- Review logs for the authentication-failure-then-rekey sequence and for hyphen-prefixed usernames.
- Audit accounts and configuration after patching, and rotate secrets where compromise indicators appear.
- In code review of protocol implementations, test message reordering, repeated phases and early initiation of dependent layers, not only malformed input.
References
- CERT Polska, "MikroTrick: technical analysis, disclosure process and use of LLM agents" - https://cert.pl/posts/2026/09/mikrotrick-analiza-techniczna/
- RFC 4253 (SSH transport layer protocol), RFC 4252 (authentication), RFC 4254 (connection protocol)
- MikroTik RouterOS release notes, September 2026
- CISA Known Exploited Vulnerabilities catalog
Top comments (0)