CVE-2026-73439
published 2026-09-16CVE-2026-73439: On affected platforms running Arista EOS, if OpenConfig is configured and running a gNMI server on the system, and if gNSI Pathz is configured and a gNSI Pathz…
PriorityP349high7.5CVSS 3.1
AVNACHPRLUINSUCHIHAH
EPSS
0.36%
27.1th percentile
On affected platforms running Arista EOS, if OpenConfig is configured and running a gNMI server on the system, and if gNSI Pathz is configured and a gNSI Pathz policy is present on the system, then gNMI may fail to correctly enforce the rules in this policy if both a group rule and a user rule for the same path is present in the policy. Under certain conditions, this can lead to an authenticated user gaining unauthorized permission to read or write gNMI paths that the Pathz policy is intended to restrict.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| arista_networks | eos | 4.33.2F – 4.33.8M | — |
| arista_networks | eos | 4.34.0F – 4.34.6M | — |
| arista_networks | eos | 4.35.0F – 4.35.5M | — |
| arista_networks | eos | 4.36.0F – 4.36.0.1F | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.07.7HIGHCVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Arista EOS up to 4.33.8M/4.34.6M/4.35.5M/4.36.0.1F gNSI Pathz Policy Enforcement privileges management (EUVD-2026-80252 / WID-SEC-2026-3287)
vuldb·2026-09-17·CVSS 7.5
CVE-2026-73439 [HIGH] Arista EOS up to 4.33.8M/4.34.6M/4.35.5M/4.36.0.1F gNSI Pathz Policy Enforcement privileges management (EUVD-2026-80252 / WID-SEC-2026-3287)
A vulnerability was found in Arista EOS up to 4.33.8M/4.34.6M/4.35.5M/4.36.0.1F. It has been declared as very critical. The impacted element is an unknown function of the component gNSI Pathz Policy Enforcement. Executing a manipulation can lead to improper privilege management.
The identification of this vulnerability is CVE-2026-73439. The attack may be launched remotely. There is no exploit available.
GHSA
On affected platforms running Arista EOS, if OpenConfig is configured and running a gNMI server on the system, and if gNSI Pathz is configured and a gNSI Pathz policy is present on the system, then gN
ghsa_unreviewed·2026-09-16
CVE-2026-73439 [HIGH] CWE-842 On affected platforms running Arista EOS, if OpenConfig is configured and running a gNMI server on the system, and if gNSI Pathz is configured and a gNSI Pathz policy is present on the system, then gN
On affected platforms running Arista EOS, if OpenConfig is configured and running a gNMI server on the system, and if gNSI Pathz is configured and a gNSI Pathz policy is present on the system, then gNMI may fail to correctly enforce the rules in this policy if both a group rule and a user rule for the same path is present in the policy. Under certain conditions, this can lead to an authenticated user gaining unauthorized permission to read or write gNMI paths that the Pathz policy is intended to restrict.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-16
Published