Clear Text Password Exposition in Arista EOS During Non-Standard Debugging
CVE-2026-73466

6MEDIUM

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-73466?

On systems running Arista EOS, an issue allows user passwords to be recorded in clear text within log files when specific non-standard debugging options are enabled. This poses a risk if the attacker has previously gained local administrative access to the device shell. Notably, the situation arises only under these unique circumstances, and there have been no reports of exploitation in the wild as of yet. The vulnerability was identified by Arista during routine checks.

Affected Version(s)

EOS 4.36.0 <= 4.36.1F

EOS 4.35.0 <= 4.35.4M

EOS 4.34.0 <= 4.34.7M

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.