Junglewise Threat Intelligence

CVE-2026-73466: Arista EOS sensitive information insertion in log files

CVE-2026-73466 · Severity: medium · CVSS 6.3 · Published 2026-09-15

Executive brief

Arista EOS, a network operating system used in enterprise switches and routers, can write sensitive credentials (user passwords, private keys, and authentication secrets) to log files when non-standard debugging features are explicitly enabled. An attacker with local administrative shell access could read these logs to obtain credentials and escalate their control over network infrastructure. No active exploitation has been reported, but the issue requires local admin access and deliberate enablement of debug features.

Technical details

The vulnerability (CVE-2026-73466) is a sensitive information disclosure issue (CWE-532) in Arista EOS where user passwords are written in plaintext to log files under specific circumstances. The root cause is insufficient filtering of sensitive data before logging when specialized non-standard debugging trace levels are explicitly enabled (e.g., MgmtSecuritySslCertKey traces on the ConfigAgent). Exploitation requires authenticated local administrative access to the device shell and manual enablement of these trace levels. An attacker with these preconditions can read log files to retrieve plaintext credentials, potentially enabling further compromise of the device and connected network. Patches are available in EOS 4.36.2F and later; earlier versions in the 4.36.x, 4.35.x, 4.34.x, 4.33.x trains and all releases in 4.32.x and 4.31.x are affected.

Affected products

  • Arista EOS 4.36.1F and earlier in 4.36.x, 4.35.4M and earlier in 4.35.x, 4.34.7M and earlier in 4.34.x, 4.33.9M and earlier in 4.33.x, all 4.32.x, all 4.31.x

Timeline

  • 2026-09-15: disclosed
  • 2026-09-09: advisory

References

Related threats