An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricted traffic during a brief window (milliseconds to seconds) between the completion of the authentication phase and the full enforcement of its assigned ACL.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

CVE-2026-77191 has been fixed in the following releases: * 4.35.1F and later releases in the 4.35.x train. * 4.34.6M and later releases in the 4.34.x train. * 4.33.8M and later releases in the 4.33.x train.


Workaround

There is no workaround available for CVE-2026-77191.

History

Mon, 14 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Description An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricted traffic during a brief window (milliseconds to seconds) between the completion of the authentication phase and the full enforcement of its assigned ACL.
Title All of the CVEs covered in this advisory apply to affected platforms running Arista EOS with 802.1X authentication and authorization enabled and Access Control Lists (ACLs) configured for per-supplicant policy enforcement. An authenticated supplicant on an
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 2.6, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-14T22:06:28.153Z

Reserved: 2026-08-20T16:41:22.053Z

Link: CVE-2026-77191

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T23:18:36.170

Modified: 2026-09-14T23:18:36.170

Link: CVE-2026-77191

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses