Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The following EOS releases contain the fix for this vulnerability: - 4.33.9M and later releases in the 4.33.x train - 4.34.8M and later releases in the 4.34.x train - 4.35.6M and later releases in the 4.35.x train - 4.36.1F and later releases in the 4.36.x train No hotfix is available for this vulnerability.
Vendor Workaround
Ensure that the privilege level 0 AAA authorization method list includes methods beyond 'none' to prevent unintended access escalation: aaa authorization exec default local group tacacs+ aaa authorization commands 0 default local group tacacs+ To detect potential exploitation, enable AAA accounting and monitor logs for cases where a user's privilege level in gRPC requests does not match their defined privilege level (e.g., a user with privilege 9 appearing as priv-lvl=0 in gRPC requests).
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 16 Sep 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On affected EOS platforms with AAA-based gRPC authorization enabled for OpenConfig, gRPC requests of an authenticated user to OpenConfig may use the wrong privilege level, resulting in an authorization using the wrong AAA method list. This does not impact non-gRPC OpenConfig requests such as NETCONF. | |
| Title | Security Advisory 0163 | |
| Weaknesses | CWE-266 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-09-16T08:01:20.911Z
Reserved: 2026-08-12T16:45:03.511Z
Link: CVE-2026-73461
No data.
Status : Received
Published: 2026-09-16T09:17:05.147
Modified: 2026-09-16T09:17:05.147
Link: CVE-2026-73461
No data.
OpenCVE Enrichment
No data.