{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-73456","assignerOrgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","state":"PUBLISHED","assignerShortName":"Arista","dateReserved":"2026-08-12T16:45:03.510Z","datePublished":"2026-09-16T18:54:59.526Z","dateUpdated":"2026-09-17T11:39:23.874Z"},"containers":{"cna":{"providerMetadata":{"orgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","shortName":"Arista","dateUpdated":"2026-09-16T18:54:59.526Z"},"title":"Under certain circumstances, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch.","datePublic":"2026-09-09T18:52:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-94","description":"CWE-94 Improper Control of Generation of Code ('Code Injection')","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-242","descriptions":[{"lang":"en","value":"CAPEC-242 Code Injection"}]}],"affected":[{"vendor":"Arista Networks","product":"EOS","platforms":["710 Series","720D Series","720XP/722XPM Series","750X Series","7010TX Series","7020R/R4 Series","7130 Series running EOS","7170 Series","7050X3/X4 Series","7060X/X2/X4/X5/X6 Series","7260X/X3 Series","7280R/R2/R3/R4 Series","7300X/X3 Series","7320X Series","7358X4 Series","7368X4 Series","7388X5 Series","7500R/R2/R3 Series","7800R3/R4 Series","7700R4 Series","AWE 5000 Series","AWE 7200R Series","CloudEOS","cEOS-lab","vEOS-lab","CloudVision eXchange","virtual or physical appliance"],"versions":[{"status":"affected","version":"4.36.0","lessThanOrEqual":"4.36.1F","changes":[{"at":"4.36.2F","status":"unaffected"}],"versionType":"custom"},{"status":"affected","version":"4.35.0","lessThanOrEqual":"4.35.5M","changes":[{"at":"4.35.6M","status":"unaffected"}],"versionType":"custom"},{"status":"affected","version":"4.34.2F","lessThanOrEqual":"4.34.7M","changes":[{"at":"4.34.8M","status":"unaffected"}],"versionType":"custom"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch.</p>"}]}],"references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24714-security-advisory-0158","tags":["vendor-advisory"]}],"configurations":[{"lang":"en","value":"In order to be vulnerable to CVE-2026-73456, gNPSI must be enabled and one of the following conditions must be met:\n\n\n\n1. A gNPSI transport is configured to perform TLS (server verification) and metadata authentication is enabled:\n\n\n\nswitch> show management api gnpsi\nTransport: t2\nEnabled: yes\nServer: running on port 7001\nSource: sflow\nListening VRF default: ::\nSSL profile: P2, TLS configured\nAuthentication username priority: x509-spiffe, metadata, x509-common-name\n\n\n\n2. Or mTLS is enabled with x509-common-name authentication configured:\n\n\n\nswitch> show management api gnpsi\nTransport: t2\nEnabled: yes\nServer: running on port 7001\nSource: sflow\nListening VRF default: ::\nSSL profile: P2, mutual TLS configured\nAuthentication username priority: x509-spiffe, x509-common-name\n\n\n\nSystems remain unaffected if gNPSI is not enabled (default configuration):\n\n\n\nswitch> show management api gnpsi\nEnabled: no transports enabled","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>In order to be vulnerable to CVE-2026-73456, gNPSI must be enabled and one of the following conditions must be met:</p><p>1. A gNPSI transport is configured to perform TLS (server verification) and metadata authentication is enabled:</p><pre>switch&gt; show management api gnpsi\nTransport: t2\nEnabled: yes\nServer: running on port 7001\nSource: sflow\nListening VRF default: ::\nSSL profile: P2, TLS configured\nAuthentication username priority: x509-spiffe, metadata, x509-common-name</pre><p>2. Or mTLS is enabled with x509-common-name authentication configured:</p><pre>switch&gt; show management api gnpsi\nTransport: t2\nEnabled: yes\nServer: running on port 7001\nSource: sflow\nListening VRF default: ::\nSSL profile: P2, mutual TLS configured\nAuthentication username priority: x509-spiffe, x509-common-name</pre><p>Systems remain unaffected if gNPSI is not enabled (default configuration):</p><pre>switch&gt; show management api gnpsi\nEnabled: no transports enabled</pre>"}]}],"workarounds":[{"lang":"en","value":"To secure the agent against CVE-2026-73456, configure the service to use mutual TLS and enable only x509-spiffe authentication:\n\n\n\nmanagement security\n   ssl profile P1\n      certificate server.crt key server.key\n      trust certificate ca_client.crt\n      chain certificate ca_signing.crt\n!\nmanagement api gnpsi\n   transport grpc t2\n      ssl profile P1\n      port 7001\n      authentication username priority x509-spiffe\n      no disabled","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>To secure the agent against CVE-2026-73456, configure the service to use mutual TLS and enable only x509-spiffe authentication:</p><pre>management security\n   ssl profile P1\n      certificate server.crt key server.key\n      trust certificate ca_client.crt\n      chain certificate ca_signing.crt\n!\nmanagement api gnpsi\n   transport grpc t2\n      ssl profile P1\n      port 7001\n      authentication username priority x509-spiffe\n      no disabled</pre>"}]}],"solutions":[{"lang":"en","value":"The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73456 has been fixed in the following releases:\n\n  *  4.36.2F and later releases in the 4.36.x train\n  *  4.35.6M and later releases in the 4.35.x train\n  *  4.34.8M and later releases in the 4.34.x train","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73456 has been fixed in the following releases:</p><ul><li>4.36.2F and later releases in the 4.36.x train</li><li>4.35.6M and later releases in the 4.35.x train</li><li>4.34.8M and later releases in the 4.34.x train</li></ul>"}]}],"credits":[{"lang":"en","value":"This issue was discovered internally by Arista.","type":"finder"}],"source":{"defect":["1823956"],"advisory":"158","discovery":"INTERNAL"},"x_generator":{"engine":"Vulnogram 1.0.5"},"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseSeverity":"CRITICAL","baseScore":10,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}},{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","subConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"CRITICAL","baseScore":9.2,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2026-73456","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"total"}],"version":"2.0.3","timestamp":"2026-09-17T03:57:34.132493Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-17T11:39:23.874Z"}}]}}