Race Condition in gRPC Network Security Interface on Arista EOS
CVE-2026-73463

6MEDIUM

Key Information:

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-73463?

In instances of Arista EOS configured with multiple gRPC Network Security Interface (gNSI) transports, a race condition in the gNSI Authz service can lead to silent policy rotation failures. This presents a significant risk as authenticated users can retain unauthorized access to gRPC interfaces even after their permissions have been revoked by the new policy. Arista has not identified any malicious exploitation of this issue within customer networks, though vigilant monitoring and prompt patching are advised.

Affected Version(s)

EOS 4.36.0F <= 4.36.0.1F

EOS 4.35.0F <= 4.35.5M

EOS 4.34.0F <= 4.34.7M

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.