๐Ÿ” CVE Alert

CVE-2026-73439

HIGH 7.5

Security Advisory 0164

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

On affected platforms running Arista EOS, if OpenConfig is configured and running a gNMI server on the system, and if gNSI Pathz is configured and a gNSI Pathz policy is present on the system, then gNMI may fail to correctly enforce the rules in this policy if both a group rule and a user rule for the same path is present in the policy. Under certain conditions, this can lead to an authenticated user gaining unauthorized permission to read or write gNMI paths that the Pathz policy is intended to restrict.

CWE CWE-842
Vendor arista networks
Product eos
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for arista networks eos

Be the first to know when new high vulnerabilities affecting arista networks eos are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Arista Networks / EOS
4.33.2F โ‰ค 4.33.8M 4.34.0F โ‰ค 4.34.6M 4.35.0F โ‰ค 4.35.5M 4.36.0F โ‰ค 4.36.0.1F

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
arista.com: https://www.arista.com/en/support/advisories-notices/security-advisory/24720-security-advisory-0164