CVE-2026-19641
On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in legitimate users being unable to log in to the device. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.34%
- CWE
- CWE-116
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Affected products
- Arista Networks EOS
- Arista Networks EOS
- Arista Networks EOS
- Arista Networks EOS
Weakness type
Related vulnerabilities
- CVE-2026-20245 — Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability
- CVE-2025-55730 — XWiki Remote Macros vulnerable to remote code execution using the confluence paste code macro
- CVE-2025-55729 — XWiki Remote Macros vulnerable to remote code execution using the ConfluenceLayoutSection macro
- CVE-2026-22792 — 5ire vulnerable to Remote Code Execution (RCE)
- CVE-2025-59936 — get-jwks poisoned JWKS cache allows post-fetch issuer validation bypass
- CVE-2025-59158 — Coolify has Stored XSS in Project Name
- CVE-2026-32754 — FreeScout: Stored XSS via Unescaped Email Template Rendering ({!! $thread->body !!})
- CVE-2025-40547 — SolarWinds Serv-U Logic Abuse - Remote Code Execution Vulnerability