Junglewise Threat Intelligence

CVE-2026-19640: Arista EOS gNMI incorrect authorization in OpenConfig

CVE-2026-19640 · Severity: medium · CVSS 4.2 · Published 2026-09-16

Executive brief

Arista EOS is network operating system used in switches and routers to manage data center and enterprise networks. An authenticated user accessing the gNMI management interface may receive incorrect authorization results, allowing them to perform operations beyond their assigned permissions. This could lead to unauthorized configuration changes or access to sensitive network data.

Technical details

This is an authorization bypass vulnerability (CWE-863) in the gNMI (gRPC Network Management Interface) implementation within Arista EOS. An authenticated user with access to OpenConfig/Octa via gNMI may receive incorrect authorization results due to a flaw in the authorization logic. The vulnerability requires gNMI to be enabled with OpenConfig configuration and AAA authorization policies in place; it does not require special network access as gNMI runs on port 6030 by default. An attacker can escalate their privileges to perform operations beyond their authorized scope. Arista has released patched versions and recommends disabling mTLS-based authentication or killing gNMI subscriptions when AAA policies change as a workaround.

Affected products

  • Arista EOS 4.24.x through 4.36.0.1F (4.36.x train), 4.35.x through 4.35.5M, 4.34.x through 4.34.7M, 4.33.x through 4.33.8M

Timeline

  • 2026-09-09: disclosed: Initial advisory release
  • 2026-09-16: other: CVE published to NVD
  • 2026-09-22: other: Advisory updated with CSAF JSON file

References

Related threats