{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-73439","assignerOrgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","state":"PUBLISHED","assignerShortName":"Arista","dateReserved":"2026-08-12T16:39:35.977Z","datePublished":"2026-09-16T08:09:11.553Z","dateUpdated":"2026-09-17T03:56:54.834Z"},"containers":{"cna":{"providerMetadata":{"orgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","shortName":"Arista","dateUpdated":"2026-09-16T08:09:11.553Z"},"datePublic":"2026-09-09T00:00:00.000Z","title":"Security Advisory 0164","descriptions":[{"lang":"en","value":"On affected platforms running Arista EOS, if OpenConfig is configured and running a gNMI server on the system, and if gNSI Pathz is configured and a gNSI Pathz policy is present on the system, then gNMI may fail to correctly enforce the rules in this policy if both a group rule and a user rule for the same path is present in the policy. Under certain conditions, this can lead to an authenticated user gaining unauthorized permission to read or write gNMI paths that the Pathz policy is intended to restrict.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>On affected platforms running Arista EOS, if OpenConfig is configured and running a gNMI server on the system, and if gNSI Pathz is configured and a gNSI Pathz policy is present on the system, then gNMI may fail to correctly enforce the rules in this policy if both a group rule and a user rule for the same path is present in the policy. Under certain conditions, this can lead to an authenticated user gaining unauthorized permission to read or write gNMI paths that the Pathz policy is intended to restrict.</p>"}]}],"affected":[{"vendor":"Arista Networks","product":"EOS","platforms":["710 Series","720D Series","720XP/722XPM Series","750X Series","7010TX Series","7020R/R4 Series","7130 Series (EOS)","7170 Series","7050X3/X4 Series","7060X/X2/X4/X5/X6 Series","7260X/X3 Series","7280R/R2/R3/R4 Series","7300X/X3 Series","7320X Series","7358X4 Series","7368X4 Series","7388X5 Series","7500R/R2/R3 Series","7800R3/R4 Series","7700R4 Series","AWE 5000 Series","AWE 7200R Series","CloudEOS","cEOS-lab","vEOS-lab","CloudVision eXchange"],"versions":[{"version":"4.33.2F","status":"affected","versionType":"custom","lessThanOrEqual":"4.33.8M"},{"version":"4.34.0F","status":"affected","versionType":"custom","lessThanOrEqual":"4.34.6M"},{"version":"4.35.0F","status":"affected","versionType":"custom","lessThanOrEqual":"4.35.5M"},{"version":"4.36.0F","status":"affected","versionType":"custom","lessThanOrEqual":"4.36.0.1F"}],"defaultStatus":"unaffected"}],"problemTypes":[{"descriptions":[{"type":"CWE","lang":"en","cweId":"CWE-842","description":"CWE-842 Placement of User into Incorrect Group"}]}],"impacts":[{"capecId":"CAPEC-1","descriptions":[{"lang":"en","value":"CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs"}]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE"}}],"configurations":[{"lang":"en","value":"All of the following conditions must be met for this vulnerability to be exploitable:\n\n1. OpenConfig must be configured with a gNMI transport started. The running configuration will include:\n\n  management api gnmi\n    transport grpc <name>\n\n2. gNSI must be configured with the gNSI Pathz service enabled. The running configuration will include:\n\n  management api gnsi\n    service pathz\n\n3. A Pathz policy must be present on the system at /persist/sys/gnsi/pathz/policy.json, and that policy must contain at least one group rule and at least one user rule for the same path.\n\nTo verify the presence of the policy file:\n\n  switch>enable\n  switch#bash stat /persist/sys/gnsi/pathz/policy.json","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>All of the following conditions must be met for this vulnerability to be exploitable:</p><ol><li>OpenConfig must be configured with a gNMI transport started. The running configuration will include:<pre>\nmanagement api gnmi\n  transport grpc &lt;name&gt;\n</pre></li><li>gNSI must be configured with the gNSI Pathz service enabled. The running configuration will include:<pre>\nmanagement api gnsi\n  service pathz\n</pre></li><li>A Pathz policy must be present on the system at <code>/persist/sys/gnsi/pathz/policy.json</code>, and that policy must contain at least one group rule and at least one user rule for the same path.</li></ol><p>To verify the presence of the policy file:</p><pre>\nswitch&gt;enable\nswitch#bash stat /persist/sys/gnsi/pathz/policy.json\n</pre>"}]}],"workarounds":[{"lang":"en","value":"Option 1: Disable gNSI Pathz entirely:\n\n  switch#configure\n  switch(config)#management api gnsi\n  switch(config-mgmt-api-gnsi)#no service pathz\n\nOption 2: Push a new gNSI Pathz policy that does not contain any group rules, using only user-principal rules. To push a new policy via grpcurl:\n\n  grpcurl -protoset ./pathz.proto.pb -H 'username:$USER' -v -d @ -plaintext $TARGET:$PORT gnsi.pathz.v1.Pathz/Rotate << EOF\n  {\n   \"upload_request\": {\n     \"version\": \"<version>\",\n     \"created_on\": <timestamp>,\n     \"policy\": <policy>\n   }\n  }\n  {\n   \"finalize_rotation\": {}\n  }\n  EOF\n\nEnsure all rules in the policy use \"user\" as the principal rather than \"group\" to avoid triggering this vulnerability.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p><strong>Option 1:</strong> Disable gNSI Pathz entirely:</p><pre>\nswitch#configure\nswitch(config)#management api gnsi\nswitch(config-mgmt-api-gnsi)#no service pathz\n</pre><p><strong>Option 2:</strong> Push a new gNSI Pathz policy that does not contain any group rules, using only user-principal rules. To push a new policy via grpcurl:</p><pre>\ngrpcurl -protoset ./pathz.proto.pb -H 'username:$USER' -v -d @ -plaintext $TARGET:$PORT gnsi.pathz.v1.Pathz/Rotate &lt;&lt; EOF\n{\n \"upload_request\": {\n   \"version\": \"&lt;version&gt;\",\n   \"created_on\": &lt;timestamp&gt;,\n   \"policy\": &lt;policy&gt;\n }\n}\n{\n \"finalize_rotation\": {}\n}\nEOF\n</pre><p>Ensure all rules in the policy use <code>user</code> as the principal rather than <code>group</code> to avoid triggering this vulnerability.</p>"}]}],"solutions":[{"lang":"en","value":"The following EOS releases contain the fix for this vulnerability:\n  - 4.33.9M and later releases in the 4.33.x train\n  - 4.34.7M and later releases in the 4.34.x train\n  - 4.35.6M and later releases in the 4.35.x train\n  - 4.36.1F and later releases in the 4.36.x train\n\nNo hotfix is available for this vulnerability.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>The following EOS releases contain the fix for this vulnerability:</p><ul><li>4.33.9M and later releases in the 4.33.x train</li><li>4.34.7M and later releases in the 4.34.x train</li><li>4.35.6M and later releases in the 4.35.x train</li><li>4.36.1F and later releases in the 4.36.x train</li></ul><p>No hotfix is available for this vulnerability.</p>"}]}],"source":{"defects":["BUG 1602638"],"advisory":"Security Advisory 0164","discovery":"INTERNAL"},"references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24720-security-advisory-0164","name":"Arista Networks Security Advisory 0164","tags":["vendor-advisory"]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-16T00:00:00+00:00","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3","id":"CVE-2026-73439"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-17T03:56:54.834Z"}}]}}