CVE-2026-75944
Received Received - Intake

Race Condition in Arista EOS ACL Enforcement

Vulnerability report for CVE-2026-75944, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-15

Assigner: Arista Networks, Inc.

Description

A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the AclAgent subsequently restarts, this stale entry may be applied to new supplicants, resulting in incorrect access control enforcement. User interaction (an AclAgent restart by an administrator) is required for the unintended behavior to take effect.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-15
Generated
2026-10-05
AI Q&A
2026-09-15
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-459 The product does not properly "clean up" and remove temporary or supporting resources after they have been used.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a race condition during supplicant re-authentication that can leave a stale ACL entry in the system. If the AclAgent restarts afterward, this stale entry might be incorrectly applied to new supplicants, causing improper access control enforcement. Administrator intervention is required for exploitation.

Detection Guidance

This vulnerability involves a race condition during supplicant re-authentication leading to stale ACL entries. Detection requires monitoring for stale ACL entries and AclAgent restarts. Check system logs for AclAgent restarts and inspect ACL configurations for inconsistencies. No specific commands are provided in the context.

Impact Analysis

The impact includes incorrect access control enforcement due to stale ACL entries being applied to new supplicants. This could allow unauthorized access or deny legitimate access, depending on the stale entry's nature. The vulnerability requires an administrator to restart the AclAgent for exploitation.

Compliance Impact

This vulnerability could lead to incorrect access control enforcement, potentially violating data protection requirements under standards like GDPR and HIPAA. Unauthorized access due to stale ACL entries may result in unauthorized data exposure or processing, which is a compliance risk.

Mitigation Strategies

Avoid restarting the AclAgent unless necessary. If a restart is required, verify ACL entries for stale or incorrect rules before applying them to new supplicants.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75944. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart