---
id: CVE-2026-73463
title: >-
  On affected platforms running Arista EOS, when multiple gRPC Network Security
  Interface (gNSI) transports are configured, a race condition in the gNSI Authz
  service may cause a policy rotation to fail silently
summary: >-
  On affected platforms running Arista EOS, when multiple gRPC Network Security
  Interface (gNSI) transports are configured, a race condition in the gNSI Authz
  service may cause a policy rotation to fail silently. An authenticated user
  whos…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-362
vendor: Arista Networks
product: EOS
affected:
  - EOS >= 4.36.0F <= 4.36.0.1F
  - EOS >= 4.35.0F <= 4.35.5M
  - EOS >= 4.34.0F <= 4.34.7M
  - EOS >= 4.33.0F <= 4.33.8M
  - EOS >= 4.32.0F <= 4.32.11M
  - EOS >= 4.31.0F <= 4.31.10M
published: '2026-09-16'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:08:50.420'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73463'
references:
  - url: >-
      https://www.arista.com/en/support/advisories-notices/security-advisory/24725-security-advisory-0169
    label: psirt@arista.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-16T13:59:22.097938Z'
ingestedAt: '2026-09-16T09:53:11.597Z'
epss: 0.00214
epssPercentile: 0.10329
---

## Overview

On affected platforms running Arista EOS, when multiple gRPC Network Security Interface (gNSI) transports are configured, a race condition in the gNSI Authz service may cause a policy rotation to fail silently. An authenticated user whose access was revoked by the new policy may retain unauthorized access to gRPC interfaces. This does not affect Bootz.

This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
