gRPC Network Security Interface Vulnerability in Arista EOS
CVE-2026-73445

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-73445?

An issue has been identified in the gRPC Network Security Interface (gNSI) on Arista EOS platforms, potentially allowing an uploaded Authz policy to become unintentionally active in the ongoing RPC stream. This vulnerability does not affect the Bootz feature. Discovered internally by Arista, there are currently no reported cases of exploitation within customer environments. Organizations utilizing Arista EOS should monitor this vulnerability for any related updates to maintain network security.

Affected Version(s)

EOS 4.36.0F <= 4.36.0.1F

EOS 4.35.0F <= 4.35.5M

EOS 4.34.0F <= 4.34.7M

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.