---
id: CVE-2026-73447
title: >-
  A privileged attacker can exploit certain operation to execute arbitrary
  commands with root privileges, leading to full device compromise
summary: >-
  A privileged attacker can exploit certain operation to execute arbitrary
  commands with root privileges, leading to full device compromise. An
  authenticated user can exploit gRPC Network Security Interface (gNSI) Certz
  service on Arista E…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: Arista Networks
product: EOS
affected:
  - EOS >= 4.30.2F < 4.31.0F
  - EOS >= 4.31.0F < 4.32.0F
  - EOS >= 4.32.0F < 4.33.0F
  - EOS >= 4.33.0F <= 4.33.8M
  - EOS >= 4.34.0F <= 4.34.7M
  - EOS >= 4.35.0F <= 4.35.5M
  - EOS >= 4.36.0F <= 4.36.0.1F
published: '2026-09-16'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T12:18:25.707'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73447'
references:
  - url: >-
      https://www.arista.com/en/support/advisories-notices/security-advisory/24718-security-advisory-0162
    label: psirt@arista.com
tags:
  - nvd
  - cve.org
epss: 0.00756
epssPercentile: 0.5371
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-17T03:57:00.368238Z'
ingestedAt: '2026-09-16T06:51:06.264Z'
---

## Overview

A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full device compromise. An authenticated user can exploit gRPC Network Security Interface (gNSI) Certz service on Arista EOS-based products to escalate privileges and execute arbitrary OS commands via a crafted Certz Rotate request. The Bootz service is also affected.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
