Junglewise Threat Intelligence

CVE-2026-75943: Arista EOS 802.1X ACL enforcement bypass on supplicant removal

CVE-2026-75943 · Severity: low · CVSS 2.6 · Published 2026-09-14

Technologies: Arista Eos. Vendors: Arista.

Executive brief

Arista EOS switches can briefly allow authenticated network devices (supplicants) to send traffic without access control enforcement when they are removed from the network or their session times out. For a brief window of milliseconds to seconds, traffic may bypass intended network segmentation policies. This affects only deployments using 802.1X authentication with per-device access control lists (ACLs) configured.

Technical details

This is a missing authorization / incomplete cleanup vulnerability (CWE-862, CWE-459) in Arista EOS when handling 802.1X supplicant removal. When an authenticated supplicant is removed via the "clear dot1x host all" CLI command or due to session timeout, a race condition or state-management flaw causes a brief window during which traffic from that supplicant passes without the intended ACL policy enforcement. The attack requires an authenticated supplicant on an adjacent network segment with 802.1X authenticator mode and per-supplicant ACL-based authorization enabled. An attacker with an authenticated supplicant session can send unrestricted traffic during the enforcement gap. Arista states no malicious exploitation has been observed in customer networks. Fixed versions are available: EOS 4.36.2F and later (4.36.x), 4.35.6M and later (4.35.x), 4.34.8M and later (4.34.x), and 4.33.10M and later (4.33.x).

Affected products

  • Arista EOS 4.36.1F and below in 4.36.x train, 4.35.5M and below in 4.35.x train, 4.34.7.1M and below in 4.34.x train, 4.33.9M and below in 4.33.x train, and all prior releases

Timeline

  • 2026-09-09: disclosed: Arista Security Advisory 0150 published
  • 2026-09-14: advisory: CVE-2026-75943 published on NVD

References

Related threats