Authorization Vulnerability in Arista EOS Affecting gNMI Access
CVE-2026-19640
2.3LOW
What is CVE-2026-19640?
An authorization flaw has been identified in Arista EOS on platforms utilizing the gNMI (gRPC Network Management Interface). This vulnerability allows an authenticated user to receive incorrect authorization results, potentially granting them access beyond their assigned permissions. This issue was internally noted by Arista, and the company has stated that there have been no known malicious exploits in customer environments.
Affected Version(s)
EOS 710 Series 4.36.0F <= 4.36.0.1F
EOS 710 Series 4.35.0F <= 4.35.5M
EOS 710 Series 4.34.0F <= 4.34.7M
