Access Control Flaw in Arista EOS Disabling Pathz Policy Enforcement
CVE-2026-73439

7.7HIGH

Key Information:

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-73439?

The vulnerability in Arista EOS affects systems running the gNMI server when OpenConfig is enabled. When both group and user rules are defined for the same path in a gNSI Pathz policy, the system may not enforce the restrictions correctly. This misconfiguration can allow an authenticated user to gain unauthorized access to sensitive gNMI paths, leading to potential data breaches. Proper review and configuration of Pathz policies are essential to mitigate this risk.

Affected Version(s)

EOS 710 Series 4.33.2F <= 4.33.8M

EOS 710 Series 4.34.0F <= 4.34.6M

EOS 710 Series 4.35.0F <= 4.35.5M

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.