Network Authorization Bypass in Arista Switches
CVE-2026-77191
2.1LOW
What is CVE-2026-77191?
This vulnerability allows an authenticated device on an adjacent network to bypass network authorization policies, enabling it to send unrestricted traffic. This occurs during a brief window of time, from milliseconds to seconds, immediately following the authentication phase before the access control list (ACL) protections are fully enforced. Organizations utilizing Arista Switches should review their network security measures to ensure proper access controls are in place.
Affected Version(s)
EOS 4.35.0 <= 4.35.0.3F
EOS 4.34.0 <= 4.34.5M
EOS 0.0.0 <= 4.33.7.1M
References
CVSS V4
Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Those issues were discovered internally by Arista, and the company is not aware of any malicious exploitation of these vulnerabilities in customer networks.
