Race Condition Vulnerability in Arista Access Control System
CVE-2026-75944

5.6MEDIUM

Key Information:

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-75944?

A race condition has been identified within Arista's Access Control System during the re-authentication process of supplicants. This flaw can lead to the presence of a stale Access Control List (ACL) entry, which may persist across system restarts. If an AclAgent is restarted by an administrator, this outdated entry could then be incorrectly applied to new supplicants, thereby compromising the intended access control measures. This issue emphasizes the importance of proper management and monitoring of access control systems to prevent unauthorized access.

Affected Version(s)

EOS 4.36.0 <= 4.36.1F

References

CVSS V4

Score:
5.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Those issues were discovered internally by Arista, and the company is not aware of any malicious exploitation of these vulnerabilities in customer networks.
.