Authorization Vulnerability in Arista EOS Affecting gNMI Access
CVE-2026-19640

2.3LOW

Key Information:

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-19640?

An authorization flaw has been identified in Arista EOS on platforms utilizing the gNMI (gRPC Network Management Interface). This vulnerability allows an authenticated user to receive incorrect authorization results, potentially granting them access beyond their assigned permissions. This issue was internally noted by Arista, and the company has stated that there have been no known malicious exploits in customer environments.

Affected Version(s)

EOS 710 Series 4.36.0F <= 4.36.0.1F

EOS 710 Series 4.35.0F <= 4.35.5M

EOS 710 Series 4.34.0F <= 4.34.7M

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.