Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
CVE-2026-77191 has been fixed in the following releases: * 4.35.1F and later releases in the 4.35.x train. * 4.34.6M and later releases in the 4.34.x train. * 4.33.8M and later releases in the 4.33.x train.
Vendor Workaround
There is no workaround available for CVE-2026-77191.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 14 Sep 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricted traffic during a brief window (milliseconds to seconds) between the completion of the authentication phase and the full enforcement of its assigned ACL. | |
| Title | All of the CVEs covered in this advisory apply to affected platforms running Arista EOS with 802.1X authentication and authorization enabled and Access Control Lists (ACLs) configured for per-supplicant policy enforcement. An authenticated supplicant on an | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-09-15T13:41:05.782Z
Reserved: 2026-08-20T16:41:22.053Z
Link: CVE-2026-77191
Updated: 2026-09-15T13:41:01.100Z
Status : Received
Published: 2026-09-14T23:18:36.170
Modified: 2026-09-15T14:17:11.413
Link: CVE-2026-77191
No data.
OpenCVE Enrichment
Updated: 2026-09-15T10:00:16Z