Network Authorization Bypass in Arista Switches
CVE-2026-77191

2.1LOW

Key Information:

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-77191?

This vulnerability allows an authenticated device on an adjacent network to bypass network authorization policies, enabling it to send unrestricted traffic. This occurs during a brief window of time, from milliseconds to seconds, immediately following the authentication phase before the access control list (ACL) protections are fully enforced. Organizations utilizing Arista Switches should review their network security measures to ensure proper access controls are in place.

Affected Version(s)

EOS 4.35.0 <= 4.35.0.3F

EOS 4.34.0 <= 4.34.5M

EOS 0.0.0 <= 4.33.7.1M

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Those issues were discovered internally by Arista, and the company is not aware of any malicious exploitation of these vulnerabilities in customer networks.
.