CVE-2026-77191: All of the CVEs covered in this advisory apply to affected platforms running Arista EOS with 802.1X authentication and authorization enabled and Access Control Lists (ACLs) configured for per-supplicant policy enforcement. An authenticated supplicant on an
An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricted traffic during a brief window (milliseconds to seconds) between the completion of the authentication phase and the full enforcement of its assigned ACL.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.33.8M - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.34.6M - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.35.1F
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Affected platforms must be running Arista EOS with 802.1X authentication and authorization enabled and ACLs configured for per-supplicant policy enforcement. The issue concerns authenticated supplicants on an adjacent network.
What access does an attacker need to exploit the issue?
An attacker must be an authenticated supplicant on an adjacent network. Exploitation occurs in the brief interval, ranging from milliseconds to seconds, after authentication completes but before the assigned ACL is fully enforced.
What is the potential impact during the exposure window?
The authenticated supplicant may bypass the intended network authorization policy and send unrestricted traffic until its assigned ACL is fully enforced.