---
id: CVE-2026-19640
title: >-
  On affected platforms running Arista EOS, an authenticated user with access to
  the gNMI (gRPC Network Management Interface) may receive incorrect
  authorization results, potentially allowing access beyond their currently
  assigned permissi…
summary: >-
  On affected platforms running Arista EOS, an authenticated user with access to
  the gNMI (gRPC Network Management Interface) may receive incorrect
  authorization results, potentially allowing access beyond their currently
  assigned permissi…
severity: medium
cvss: 4.2
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-863
vendor: Arista Networks
product: EOS
affected:
  - EOS >= 4.36.0F <= 4.36.0.1F
  - EOS >= 4.35.0F <= 4.35.5M
  - EOS >= 4.34.0F <= 4.34.7M
  - EOS >= 4.33.0F <= 4.33.8M
  - EOS >= 4.24.0F < 4.33.0F
published: '2026-09-16'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:08:50.420'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19640'
references:
  - url: >-
      https://www.arista.com/en/support/advisories-notices/security-advisory/24726-security-advisory-0170
    label: psirt@arista.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-16T13:55:08.082343Z'
ingestedAt: '2026-09-16T09:53:11.607Z'
epss: 0.00192
epssPercentile: 0.09151
---

## Overview

On affected platforms running Arista EOS, an authenticated user with access to the gNMI (gRPC Network Management Interface) may receive incorrect authorization results, potentially allowing access beyond their currently assigned permissions.

This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
