SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-19641

MEDIUM · CVSS 5.3 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Arista EOS platforms with password authentication are vulnerable to a flaw that allows specially crafted passwords to create orphan authentication sessions, potentially exhausting authentication resources. This can lead to denial of service for legitimate users, preventing them from logging into the device. Organizations using Arista EOS should prioritize remediation to ensure uninterrupted access for their users.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19641
Severity
MEDIUM
CVSS
5.3
EPSS
0.34%

Original NVD Description

On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in legitimate users being unable to log in to the device. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.