Junglewise Threat Intelligence

CVE-2026-75945: Arista EOS race condition in 802.1X authentication state management

CVE-2026-75945 · Severity: low · CVSS 2.6 · Published 2026-09-14

Technologies: Arista Eos. Vendors: Arista.

Executive brief

Arista EOS is network operating software that manages authentication and access control on enterprise switches. A race condition can allow an authenticated user to remain authorized even after an administrator has attempted to revoke their access via the "clear dot1x host all" command, potentially enabling brief unauthorized network access. The impact is limited to temporary circumvention of network segmentation policies in environments using per-supplicant ACLs.

Technical details

This race condition (CWE-459 Incomplete Cleanup) affects Arista EOS when 802.1X authentication and ACL-based authorization are configured. When the "clear dot1x host all" command is issued to revoke supplicant access, a timing window exists where the authorization state is not properly cleared before policy enforcement checks occur, allowing the supplicant's traffic to bypass ACL enforcement for milliseconds to seconds. The vulnerability requires 802.1X to be enabled in authenticator mode with per-supplicant ACLs; deployments using 802.1X without ACL-based per-supplicant policy enforcement are not affected. Exploitation is limited to authenticated adjacent network segments and requires authenticated access. Patches are available in EOS 4.36.1F and later releases.

Affected products

  • Arista EOS 4.36.1F and below in 4.36.x; 4.35.5M and below in 4.35.x; 4.34.7.1M and below in 4.34.x; 4.33.9M and below in 4.33.x; and all prior releases

Timeline

  • 2026-09-09: disclosed
  • 2026-09-22: advisory: CSAF JSON file added to advisory

References

Related threats