Junglewise Threat Intelligence

CVE-2026-73454: Arista EOS gNSI Credentialz privilege escalation

CVE-2026-73454 · Severity: high · CVSS 8.1 · Published 2026-09-16

Technologies: Arista Eos. Vendors: Arista.

Executive brief

Arista EOS network operating system contains a vulnerability in its gRPC Network Security Interface (gNSI) credential management feature that allows attackers with login credentials to modify account properties and gain unauthorized elevated privileges. An authenticated attacker could escalate their access level beyond what administrators intended, potentially compromising network device management and control.

Technical details

The vulnerability is a command injection flaw (CWE-77) in the gNSI Credentialz service affecting Arista EOS versions 4.36.0.1F and below (and certain older release trains). A specially crafted request sent to the gNSI service can cause unintended modifications to user account properties including role and privilege level. The attack requires: (1) gNSI Credentialz to be explicitly enabled (disabled by default), and (2) the attacker to have valid login credentials (PR:L). An authenticated network-reachable attacker can modify target account permissions to escalate privileges or gain unintended access. Fixes are available in EOS 4.36.1F, 4.35.6M, 4.34.7.1M, and 4.33.9M or later.

Affected products

  • Arista EOS 4.36.0.1F and below in 4.36.x, 4.35.5M and below in 4.35.x, 4.34.7M and below in 4.34.x, 4.33.8M and below in 4.33.x, all 4.32.x, 4.31.x, 4.30.x

Timeline

  • 2026-09-09: disclosed
  • 2026-09-09: patched: Patches released for EOS 4.36.1F, 4.35.6M, 4.34.7.1M, 4.33.9M and later

References

Related threats