CVE-2026-73461
largeIncorrect Privilege Assignment in Arista EOS gRPC OpenConfig AAA Authorization
Arista EOS contains a privilege-assignment flaw (CWE-266) in which gRPC requests from an authenticated user to the OpenConfig interface may be evaluated at the wrong privilege level, causing authorization to run against the wrong AAA method list. It is triggered when a user sends a gRPC OpenConfig request to a device on which AAA-based gRPC authorization for OpenConfig is enabled; non-gRPC OpenConfig transports such as NETCONF are not affected. An attacker holding valid credentials could gain authorization for configuration changes or operations beyond their intended privileges, consistent with the 9.4 CVSS 4.0 score's high confidentiality, integrity, and availability impact. Only Arista EOS platforms with this specific gRPC/OpenConfig AAA configuration are affected. No exploitation in the wild, public proof-of-concept, or CISA KEV listing is currently known.
What to do: Inventory EOS devices for OpenConfig over gRPC and check whether AAA-based gRPC authorization is enabled; where present, restrict gRPC access to trusted management hosts via ACLs or management-plane filtering while awaiting the fixed release, since specific fixed EOS versions are not listed in the available data. Review AAA method lists and audit recent gRPC-authenticated sessions for activity performed at unintended privilege levels.
| Arista Networks EOS (Extensible Operating System) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
On affected EOS platforms with AAA-based gRPC authorization enabled for OpenConfig, gRPC requests of an authenticated user to OpenConfig may use the wrong privilege level, resulting in an authorization using the wrong AAA method list. This does not impact non-gRPC OpenConfig requests such as NETCONF.
- Weakness
- CWE-266
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.