New environments are given a new, uniquely named security group (SG) by the service. Additional SGs can be supplied to allow access to the environment. There is a situation you can get into if you supply an SG auto-created by another environment which might be what is happening here? The documentation has a note that calls out how to avoid this dependency issue [1]. If that is not what is happening here, I am happy to help but might need more information about your environments.
[1] - https://docs.aws.amazon.com/elasticbeanstalk/latest/dg/using...