---
id: CVE-2026-75944
title: >-
  A race condition during supplicant re-authentication may leave a stale ACL
  entry that persists in the system
summary: >-
  A race condition during supplicant re-authentication may leave a stale ACL
  entry that persists in the system. If the AclAgent subsequently restarts, this
  stale entry may be applied to new supplicants, resulting in incorrect access
  contro…
severity: low
cvss: 2.6
cvssVector: 'CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-459
vendor: Arista Networks
product: EOS
affected:
  - EOS >= 4.36.0 <= 4.36.1F
published: '2026-09-14'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T20:36:52.890'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-75944'
references:
  - url: >-
      https://www.arista.com/en/support/advisories-notices/security-advisory/24706-security-advisory-0150
    label: psirt@arista.com
tags:
  - nvd
  - cve.org
epss: 0.00146
epssPercentile: 0.04248
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T23:06:11.210257Z'
ingestedAt: '2026-09-14T23:17:06.517Z'
---

## Overview

A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the AclAgent subsequently restarts, this stale entry may be applied to new supplicants, resulting in incorrect access control enforcement. User interaction (an AclAgent restart by an administrator) is required for the unintended behavior to take effect.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
