CVE-2026-77191

Summary

An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricted traffic during a brief window (milliseconds to seconds) between the completion of the authentication phase and the full enforcement of its assigned ACL.

Affected Software

VendorProductVersion RangeStatus
Arista NetworksEOS4.35.0 <= 4.35.0.3Faffected
Arista NetworksEOS4.34.0 <= 4.34.5Maffected
Arista NetworksEOS0.0.0 <= 4.33.7.1Maffected

Weaknesses

  • CWE-862: CWE-862 Missing Authorization

Workarounds

There is no workaround available for CVE-2026-77191.

References