Executive brief
Arista EOS network switches with 802.1X authentication configured may briefly allow authenticated users to send network traffic without proper access control restrictions due to a race condition between authentication completion and ACL enforcement. This creates a brief window (milliseconds to seconds) where network segmentation policies are not applied, potentially allowing unauthorized access to restricted network segments during this short period.
Technical details
CVE-2026-77191 is a missing authorization vulnerability (CWE-862) in Arista EOS occurring in the 802.1X authentication and authorization workflow. An authenticated supplicant on an adjacent network segment can exploit a race condition between the completion of the authentication phase and the full enforcement of its assigned ACL, allowing unrestricted traffic to pass during a brief window of milliseconds to seconds. The vulnerability requires 802.1X to be configured in authenticator mode with per-supplicant ACL-based authorization policies. Attack vector is adjacent network (AV:A), and the attacker must be an authenticated user (PR:L). The impact is limited to integrity of access control enforcement. Arista has confirmed no active exploitation in customer networks. Patches are available for affected EOS versions.
Affected products
- Arista EOS 4.35.0.3F and below (4.35.x), 4.34.5M and below (4.34.x), 4.33.7.1M and below (4.33.x), and all prior releases
Timeline
- 2026-09-14: disclosed
- 2026-09-09: advisory: Arista Security Advisory 0150 released