Arista NetworksCVE-2026-75944
Arista Networks EOS: race condition
Medium5.6CVE-2026-75944 · Published Sep 14, 2026 · updated Sep 16, 2026
A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the AclAgent subsequently restarts, this stale entry may be applied to new supplicants, resulting in incorrect access control enforcement. User interaction (an AclAgent restart by an administrator) is required for the unintended behavior to take effect.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| EOS Product | >= 4.36.0, <= 4.36.1F | No fix yet |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-459
More Arista Networks advisories
All Arista Networks| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 15 | On affected platforms running Arista EOS with dual switch cards and with... | Medium6.3 | No fix yet |
| Sep 15 | Arista Networks EOS: improper output encoding | Medium6.9 | No fix yet |
| Sep 14 | Arista Networks EOS: missing authorization | Low2.1 | No fix yet |
| Sep 14 | Arista Networks EOS: incomplete cleanup | Low2.1 | No fix yet |
| Sep 14 | Arista Networks EOS: race condition | Low2.1 | No fix yet |
| Sep 14 | Arista Networks EOS: improper access control | Medium5.9 | No fix yet |