Metrics
Affected Vendors & Products
No advisories yet.
Solution
The following EOS releases contain the fix for this vulnerability: - 4.33.9M and later releases in the 4.33.x train - 4.34.8M and later releases in the 4.34.x train - 4.35.6M and later releases in the 4.35.x train - 4.36.1F and later releases in the 4.36.x train No hotfix is available for this vulnerability.
Workaround
Ensure that the privilege level 0 AAA authorization method list includes methods beyond 'none' to prevent unintended access escalation: aaa authorization exec default local group tacacs+ aaa authorization commands 0 default local group tacacs+ To detect potential exploitation, enable AAA accounting and monitor logs for cases where a user's privilege level in gRPC requests does not match their defined privilege level (e.g., a user with privilege 9 appearing as priv-lvl=0 in gRPC requests).
Wed, 16 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On affected EOS platforms with AAA-based gRPC authorization enabled for OpenConfig, gRPC requests of an authenticated user to OpenConfig may use the wrong privilege level, resulting in an authorization using the wrong AAA method list. This does not impact non-gRPC OpenConfig requests such as NETCONF. | |
| Title | Security Advisory 0163 | |
| Weaknesses | CWE-266 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-09-16T14:52:25.449Z
Reserved: 2026-08-12T16:45:03.511Z
Link: CVE-2026-73461
Updated: 2026-09-16T14:52:22.433Z
Status : Received
Published: 2026-09-16T09:17:05.147
Modified: 2026-09-16T15:17:42.990
Link: CVE-2026-73461
No data.
OpenCVE Enrichment
Updated: 2026-09-16T14:15:09Z