---
schema: 1
kind: vulnerability
title: "CVE-2026-7473 — Arista EOS tunnel-decapsulation logic flaw bypasses segmentation, added to CISA KEV"
headline: "CVE-2026-7473 — Arista EOS tunnel-decapsulation logic flaw bypasses segmentation, added to CISA KEV"
summary: "Arista EOS contains an incomplete-comparison flaw (CWE-1023) in its tunnel-decapsulation logic: where a VXLAN, decap-group or GRE decapsulation config is present, the switch decapsulates and forwards tunneled packets whose destination IP matches the configured decap IP even from unexpected sources, letting an attacker …"
discovered_at: "2026-06-10T05:00:10Z"
event_date: 2026-06-09
run_id: 2026-06-10-c84347b2
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - actively-exploited
  - cisa-kev
  - auth-bypass
regions:
  - global
sectors:
  - finance
entities: []
cves:
  - id: CVE-2026-7473
    cvss: n/a
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - cisa-kev
      - patch-available
sources:
  - url: "https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advisory-0137"
    publisher: "Arista, 2026-06-09"
    role: primary
closed_sources: []
evidence:
  - quote: "Arista EOS contains an incomplete-comparison flaw (CWE-1023) in its tunnel-decapsulation logic: where a VXLAN, decap-group or GRE decapsulation config is present, the switch decapsulates and forwards tunneled packets whose destination IP matches the configured decap IP even from unexpected sources …"
    publisher: ctipilot v2 brief (migrated)
verification: single-source
sourcing_note: "migration: evidence backfilled from v2 brief body (item predates the Evidence footer field)"
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-06-10.md
---

Arista EOS contains an incomplete-comparison flaw (CWE-1023) in its tunnel-decapsulation logic: where a VXLAN, decap-group or GRE decapsulation config is present, the switch decapsulates and forwards tunneled packets whose destination IP matches the configured decap IP even from unexpected sources, letting an attacker inject traffic into a VXLAN fabric and bypass network segmentation; CISA added CVE-2026-7473 to its KEV catalog on 9 June ([Arista, 2026-06-09](https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advisory-0137)). Relevant to datacenter-fabric operators in CH/EU finance and government. Apply Arista SA-0137 and add decap source-IP validation/access-lists on VTEP interfaces (T1599.001).
