---
id: CVE-2026-73461
title: >-
  On affected EOS platforms with AAA-based gRPC authorization enabled for
  OpenConfig, gRPC requests of an authenticated user to OpenConfig may use the
  wrong privilege level, resulting in an authorization using the wrong AAA
  method list
summary: >-
  On affected EOS platforms with AAA-based gRPC authorization enabled for
  OpenConfig, gRPC requests of an authenticated user to OpenConfig may use the
  wrong privilege level, resulting in an authorization using the wrong AAA
  method list. Th…
severity: high
cvss: 8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-266
vendor: Arista Networks
product: EOS
affected:
  - EOS >= 4.29.0F < 4.30.0F
  - EOS >= 4.30.0F < 4.31.0F
  - EOS >= 4.31.0F < 4.32.0F
  - EOS >= 4.32.0F <= 4.32.11M
  - EOS >= 4.33.0F <= 4.33.8M
  - EOS >= 4.34.0F <= 4.34.7M
  - EOS >= 4.35.0F <= 4.35.5M
  - EOS >= 4.36.0F <= 4.36.0.1F
published: '2026-09-16'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T04:18:00.483'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73461'
references:
  - url: >-
      https://www.arista.com/en/support/advisories-notices/security-advisory/24719-security-advisory-0163
    label: psirt@arista.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-16T14:52:18.693471Z'
epss: 0.00394
epssPercentile: 0.30924
ingestedAt: '2026-09-16T08:52:29.601Z'
---

## Overview

On affected EOS platforms with AAA-based gRPC authorization enabled for OpenConfig, gRPC requests of an authenticated user to OpenConfig may use the wrong privilege level, resulting in an authorization using the wrong AAA method list. This does not impact non-gRPC OpenConfig requests such as NETCONF.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
