---
id: CVE-2026-19641
title: >-
  On affected platforms running Arista EOS with password authentication
  configured, a specially crafted password can create orphan authentication
  sessions
summary: >-
  On affected platforms running Arista EOS with password authentication
  configured, a specially crafted password can create orphan authentication
  sessions. Repeated exploitation of this issue can exhaust available
  authentication resources,…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-116
vendor: Arista Networks
product: EOS
affected:
  - EOS >= 4.36.0 <= 4.36.0F
  - EOS >= 4.35.0 <= 4.35.5M
  - EOS >= 4.34.0 <= 4.34.7.1M
  - EOS >= 0.0.0 <= 4.33.8M
published: '2026-09-15'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:08:50.420'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19641'
references:
  - url: >-
      https://www.arista.com/en/support/advisories-notices/security-advisory/24708-security-advisory-0152
    label: psirt@arista.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-15T19:24:56.712841Z'
ingestedAt: '2026-09-15T18:41:59.182Z'
epss: 0.00343
epssPercentile: 0.27895
---

## Overview

On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in legitimate users being unable to log in to the device.

This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
