CVE-2026-75944
A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the AclAgent subsequently restarts, this stale entry may be applied to new supplicants, resulting in incorrect access control enforcement. User interaction (an AclAgent restart by an administrator) is required for the unintended behavior to take effect.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.6
- CVSS vector
- CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
- EPSS probability
- 0.15%
- CWE
- CWE-459
- Published
- 2026-09-14
- Last modified
- 2026-09-15
Affected products
- Arista Networks EOS
Weakness type
Related vulnerabilities
- CVE-2025-31650 — Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
- CVE-2023-36468 — Upgrading doesn't prevent exploiting vulnerable XWiki documents
- CVE-2026-28268 — Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse
- CVE-2025-59781 — BIG-IP DNS cache vulnerability
- CVE-2025-21609 — SiYuan has an arbitrary file deletion vulnerability
- CVE-2022-39368 — Californium Failing DTLS handshakes causes Data Loss due to throttling blocking processing of records
- CVE-2021-36205 — Metasys session token
- CVE-2025-43711 — Tunnelblick 3.5beta06 before 7.0, when incompletely uninstalled, allows attackers to execute arbitrary code as root (upo