Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-73461: Arista EOS gRPC OpenConfig may use wrong privileges

CVE-2026-73461 · published today
Summary

Arista EOS switches that have AAA‑based gRPC authentication turned on for OpenConfig can give an authenticated user the incorrect level of access when they use gRPC. This means a user might be able to perform actions they should not be allowed to do, while other access methods such as NETCONF are not affected. Check the device configuration and make sure the correct AAA method list is used, or disable gRPC authentication for OpenConfig until the issue is fixed.

What to do
  • Update arista networks eos to version 4.30.0F or later.
Affected software
VendorProductAffected versions
arista networks eos < 4.30.0F
Original advisory text
Security Advisory 0163
On affected EOS platforms with AAA-based gRPC authorization enabled for OpenConfig, gRPC requests of an authenticated user to OpenConfig may use the wrong privilege level, resulting in an authorization using the wrong AAA method list. This does not impact non-gRPC OpenConfig requests such as NETCONF.
Severity
9.4 Critical
CVSS 3.1: 8.0 (MITRE)
Type
CWE-266Incorrect Privilege Assignment
Timeline
Published16 Sep 2026
Updated16 Sep 2026
First seen16 Sep 2026
Sources
CVE-2026-73461 · MITRE
Track software like this
Free during beta