Junglewise Threat Intelligence

CVE-2026-75944: Arista EOS ACL race condition in supplicant re-authentication

CVE-2026-75944 · Severity: low · CVSS 2.6 · Published 2026-09-14

Technologies: Arista Eos. Vendors: Arista.

Executive brief

Arista EOS switches support 802.1X network authentication with per-user access control lists (ACLs) to enforce network segmentation policies. A race condition during re-authentication can leave stale ACL rules in the system that persist even after an administrator restarts the ACL agent, causing those outdated rules to be incorrectly applied to new authenticated users. This could allow unauthorized network access for brief periods or after a restart.

Technical details

The vulnerability is a race condition in the ACL management system that occurs during supplicant re-authentication in 802.1X-enabled environments. The root cause is incomplete cleanup (CWE-459) of stale ACL entries when a supplicant re-authenticates; under specific timing conditions, an old ACL rule may persist in the system. The vulnerability requires 802.1X to be configured in authenticator mode with ACL-based per-supplicant authorization, and an administrator must manually restart the AclAgent process for the stale entry to be applied to new supplicants, resulting in incorrect access control enforcement. The attack is adjacent-network only and requires an authenticated supplicant, limiting direct exploitability. Patches are available in EOS 4.36.1F and later for the 4.36.x train.

Affected products

  • Arista EOS 4.36.1F and below (all 4.36.x, 4.35.x, 4.34.x, 4.33.x and prior)

Timeline

  • 2026-09-09: disclosed: Arista Security Advisory 0150 released
  • 2026-09-14: advisory: CVE-2026-75944 published in NVD

References

Related threats