CVE-2026-75944: A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the AclAgent subsequently restarts, this stale entry may be applied to new supplicants, resulting in incorrect access control enforcement. User
A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the AclAgent subsequently restarts, this stale entry may be applied to new supplicants, resulting in incorrect access control enforcement. User interaction (an AclAgent restart by an administrator) is required for the unintended behavior to take effect.
Event History
Frequently Asked Questions
What conditions are required for the incorrect ACL enforcement to occur?
A stale ACL entry must first be left behind during supplicant re-authentication. The AclAgent must subsequently be restarted by an administrator before that stale entry can be applied to new supplicants.
Who is most likely to be exposed to this issue?
Exposure is limited to environments where supplicants re-authenticate and the AclAgent is later restarted. The CVSS vector indicates adjacent-network access, high attack complexity, and low privileges are required; no direct user interaction with the attacker is required.