Skip to content
Arista NetworksCVE-2026-75944

Arista Networks EOS: race condition

Medium5.6CVE-2026-75944 · Published Sep 14, 2026 · updated Sep 16, 2026

A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the AclAgent subsequently restarts, this stale entry may be applied to new supplicants, resulting in incorrect access control enforcement. User interaction (an AclAgent restart by an administrator) is required for the unintended behavior to take effect.

Arista Networks advisory

Affected versions

PackageAffectedFixed in
EOS
Product
>= 4.36.0, <= 4.36.1FNo fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-459

More Arista Networks advisories

All Arista Networks
Advisory
On affected platforms running Arista EOS with dual switch cards and with...
Medium6.3Sep 15
Arista Networks EOS: improper output encoding
Medium6.9Sep 15
Arista Networks EOS: missing authorization
Low2.1Sep 14
Arista Networks EOS: incomplete cleanup
Low2.1Sep 14
Arista Networks EOS: race condition
Low2.1Sep 14
Arista Networks EOS: improper access control
Medium5.9Sep 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.