CVE-2026-73463: Security Advisory 0169
On affected platforms running Arista EOS, when multiple gRPC Network Security Interface (gNSI) transports are configured, a race condition in the gNSI Authz service may cause a policy rotation to fail silently. An authenticated user whose access was revoked by the new policy may retain unauthorized access to gRPC interfaces. This does not affect Bootz.
This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.33.9M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.34.7.1M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.35.6M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.36.1F - Compensating control
Because no hotfix is available, mitigate by monitoring and validating gRPC Network Security Interface (gNSI) Authz policy rotation behavior on affected platforms with multiple gNSI transports configured; ensure policy rotation succeeds rather than failing silently.
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Affected Arista EOS platforms are exposed only when multiple gNSI transports are configured. Bootz is not affected.
What must happen for unauthorized access to persist?
A policy rotation must encounter the race condition and fail silently. An authenticated user whose access is revoked by the new policy may then retain access to gRPC interfaces.
Does exploitation require an unauthenticated attacker?
No. The described impact concerns a user who is already authenticated and whose access should have been revoked by a new policy.
Is there evidence of exploitation in customer networks?
Arista states that it is not aware of malicious exploitation of this vulnerability in customer networks.