Junglewise Threat Intelligence

CVE-2026-73461: Arista EOS incorrect privilege assignment in gRPC OpenConfig

CVE-2026-73461 · Severity: high · CVSS 8 · Published 2026-09-16

Technologies: Arista Eos. Vendors: Arista.

Executive brief

Arista EOS network switches support gRPC-based OpenConfig management, which authenticates users and enforces role-based access control. When AAA-based authorization is enabled for gRPC OpenConfig requests, a flaw causes authenticated users' privilege levels to be misapplied, potentially allowing a high-privilege user to execute operations at incorrect privilege levels or vice versa. This could lead to unauthorized configuration changes or data exposure depending on the authorization policies in place.

Technical details

This vulnerability is a privilege assignment flaw (CWE-266) in Arista EOS's gRPC authorization mechanism for OpenConfig. When AAA-based gRPC request authorization is enabled with mutual TLS on an OpenConfig gRPC transport, authenticated users' privilege levels are incorrectly assigned during authorization, resulting in the wrong AAA method list being applied. The vulnerability requires mutual TLS to be configured and gRPC authorization to be enabled; it does not affect non-gRPC OpenConfig requests such as NETCONF. An attacker with valid credentials could potentially bypass privilege-level restrictions or gain unintended access by exploiting this flaw. Patches are available in updated EOS releases.

Affected products

  • Arista EOS 4.36.0.1F and below (4.36.x), 4.35.5M and below (4.35.x), 4.34.7M and below (4.34.x), 4.33.8M and below (4.33.x), all 4.29.x, 4.30.x, 4.31.x, 4.32.x

Timeline

  • 2026-09-09: disclosed: Arista Security Advisory 0163 released
  • 2026-09-16: advisory: CVE-2026-73461 published

References

Related threats