---
id: CVE-2026-73445
title: >-
  On affected platforms running Arista EOS, an issue with the gRPC Network
  Security Interface (gNSI) Authz Rotate RPC may cause an incorrect Authz policy
  which was uploaded in the ongoing RPC stream to become active
summary: >-
  On affected platforms running Arista EOS, an issue with the gRPC Network
  Security Interface (gNSI) Authz Rotate RPC may cause an incorrect Authz policy
  which was uploaded in the ongoing RPC stream to become active. This does not
  affect B…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-20
vendor: Arista Networks
product: EOS
affected:
  - EOS >= 4.36.0F <= 4.36.0.1F
  - EOS >= 4.35.0F <= 4.35.5M
  - EOS >= 4.34.0F <= 4.34.7M
  - EOS >= 4.33.0F <= 4.33.8M
  - EOS >= 4.32.0F < 4.33.0F
  - EOS >= 4.31.0F < 4.32.0F
published: '2026-09-16'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:09:28.447'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73445'
references:
  - url: >-
      https://www.arista.com/en/support/advisories-notices/security-advisory/24723-security-advisory-0167
    label: psirt@arista.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-16T17:35:46.330735Z'
ingestedAt: '2026-09-16T09:53:11.596Z'
epss: 0.00326
epssPercentile: 0.25942
---

## Overview

On affected platforms running Arista EOS, an issue with the gRPC Network Security Interface (gNSI) Authz Rotate RPC may cause an incorrect Authz policy which was uploaded in the ongoing RPC stream to become active. This does not affect Bootz.

This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
