Skip to content
Arista NetworksCVE-2026-73463

Arista Networks EOS: race condition

Medium6.0CVE-2026-73463 · Published Sep 16, 2026

On affected platforms running Arista EOS, when multiple gRPC Network Security Interface (gNSI) transports are configured, a race condition in the gNSI Authz service may cause a policy rotation to fail silently. An authenticated user whose access was revoked by the new policy may retain unauthorized access to gRPC interfaces. This does not affect Bootz. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.

Arista Networks advisory

Affected versions

PackageAffectedFixed in
EOS
Product
>= 4.36.0F, <= 4.36.0.1FNo fix yet
>= 4.35.0F, <= 4.35.5MNo fix yet
>= 4.34.0F, <= 4.34.7MNo fix yet
>= 4.33.0F, <= 4.33.8MNo fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-362

More Arista Networks advisories

All Arista Networks
Advisory
Arista Networks EOS: remote code execution
Critical9.2Sep 16
Arista Networks EOS: secrets in logs
Medium6.0Sep 16
Arista Networks EOS: out-of-bounds read
High7.1Sep 16
Arista Networks EOS: secrets in logs
Low2.1Sep 16
Arista Networks EOS: denial of service
Medium5.3Sep 16
Arista Networks VeloCloud Edge: missing authentication
High8.7Sep 16

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.