CVE-2026-73463
published 2026-09-16CVE-2026-73463: On affected platforms running Arista EOS, when multiple gRPC Network Security Interface (gNSI) transports are configured, a race condition in the gNSI Authz…
PriorityP433medium5.3CVSS 3.1
AVNACHPRLUINSUCNIHAN
EPSS
0.20%
10.0th percentile
On affected platforms running Arista EOS, when multiple gRPC Network Security Interface (gNSI) transports are configured, a race condition in the gNSI Authz service may cause a policy rotation to fail silently. An authenticated user whose access was revoked by the new policy may retain unauthorized access to gRPC interfaces. This does not affect Bootz.
This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| arista_networks | eos | 4.31.0F – 4.31.10M | — |
| arista_networks | eos | 4.32.0F – 4.32.11M | — |
| arista_networks | eos | 4.33.0F – 4.33.8M | — |
| arista_networks | eos | 4.34.0F – 4.34.7M | — |
| arista_networks | eos | 4.35.0F – 4.35.5M | — |
| arista_networks | eos | 4.36.0F – 4.36.0.1F | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv4.06.0MEDIUMCVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Arista EOS up to 4.36.0.1F gNSI Authz service race condition (WID-SEC-2026-3441)
vuldb·2026-09-17·CVSS 5.3
CVE-2026-73463 [MEDIUM] Arista EOS up to 4.36.0.1F gNSI Authz service race condition (WID-SEC-2026-3441)
A vulnerability was found in Arista EOS up to 4.36.0.1F. It has been rated as critical. The affected element is an unknown function of the component gNSI Authz service. The manipulation leads to race condition.
This vulnerability is uniquely identified as CVE-2026-73463. The attack is possible to be carried out remotely. No exploit exists.
GHSA
On affected platforms running Arista EOS, when multiple gRPC Network Security Interface (gNSI) transports are configured, a race condition in the gNSI Authz service may cause a policy rotation to fail
ghsa_unreviewed·2026-09-16
CVE-2026-73463 [MEDIUM] CWE-362 On affected platforms running Arista EOS, when multiple gRPC Network Security Interface (gNSI) transports are configured, a race condition in the gNSI Authz service may cause a policy rotation to fail
On affected platforms running Arista EOS, when multiple gRPC Network Security Interface (gNSI) transports are configured, a race condition in the gNSI Authz service may cause a policy rotation to fail silently. An authenticated user whose access was revoked by the new policy may retain unauthorized access to gRPC interfaces. This does not affect Bootz.
This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-16
Published