SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-73449

MEDIUM · CVSS 5.9 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Arista EOS systems configured with both 802.1X port authentication and RADIUS proxy dynamic authorization are vulnerable to a low-privileged attacker on an adjacent network segment. This vulnerability allows the attacker to block critical RADIUS dynamic authorization messages, enabling unauthorized endpoints to maintain network access despite being ordered to disconnect. Organizations using these configurations should prioritize addressing this issue to prevent potential unauthorized access to their networks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-73449
Severity
MEDIUM
CVSS
5.9
EPSS
0.14%

Original NVD Description

On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet through a configured RADIUS proxy client can prevent RADIUS dynamic authorization messages, including Change-of-Authorization (CoA) and Disconnect-Requests as defined in RFC 5176, from being applied to locally authenticated 802.1X sessions. This allows an endpoint session that a RADIUS server or network access control system has ordered disconnected to remain authorized on the network. Both 802.1X port authentication with dynamic authorization and RADIUS proxy with dynamic authorization must be explicitly configured for a deployment to be exposed to this issue. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.