Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
CVE-2026-77191 has been fixed in the following releases: * 4.35.1F and later releases in the 4.35.x train. * 4.34.6M and later releases in the 4.34.x train. * 4.33.8M and later releases in the 4.33.x train.
Vendor Workaround
There is no workaround available for CVE-2026-77191.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricted traffic during a brief window (milliseconds to seconds) between the completion of the authentication phase and the full enforcement of its assigned ACL. | |
| Title | All of the CVEs covered in this advisory apply to affected platforms running Arista EOS with 802.1X authentication and authorization enabled and Access Control Lists (ACLs) configured for per-supplicant policy enforcement. An authenticated supplicant on an | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-09-14T22:06:28.153Z
Reserved: 2026-08-20T16:41:22.053Z
Link: CVE-2026-77191
No data.
Status : Received
Published: 2026-09-14T23:18:36.170
Modified: 2026-09-14T23:18:36.170
Link: CVE-2026-77191
No data.
OpenCVE Enrichment
No data.
