CVE-2026-77191: All of the CVEs covered in this advisory apply to affected platforms running Arista EOS with 802.1X authentication and authorization enabled and Access Control Lists (ACLs) configured for per-supplicant policy enforcement. An authenticated supplicant on an

Published Sep 14, 2026
·
Updated

An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricted traffic during a brief window (milliseconds to seconds) between the completion of the authentication phase and the full enforcement of its assigned ACL.

Affected Software

1 affected component
Arista EOS

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.33.8M
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.34.6M
  3. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.35.1F

Event History

Sep 14, 2026
CVE Published
via MITRE·10:06 PM
Data Sourced
via MITRE·10:06 PM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Affected platforms must be running Arista EOS with 802.1X authentication and authorization enabled and ACLs configured for per-supplicant policy enforcement. The issue concerns authenticated supplicants on an adjacent network.

2

What access does an attacker need to exploit the issue?

An attacker must be an authenticated supplicant on an adjacent network. Exploitation occurs in the brief interval, ranging from milliseconds to seconds, after authentication completes but before the assigned ACL is fully enforced.

3

What is the potential impact during the exposure window?

The authenticated supplicant may bypass the intended network authorization policy and send unrestricted traffic until its assigned ACL is fully enforced.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203