← All Advisories

Crafted gNSI Credentialz Request on Arista EOS Can Assign an Account Elevated Privileges Beyond Administrator Intent

Last refreshed2026-09-29

Status: NEW  |  Advisory ID: CVE-2026-73454

Key Details

CVECVE-2026-73454
CVSS Score / Version8.1 (High) / CVSS v3.1
Updated2026-09-17
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is none.
Classified asCWE-77 (Improper Neutralization of Special Elements used in a Command ('Command Injection'))

What to Know

On affected platforms running Arista EOS with gRPC Network Security Interface (gNSI) Credentialz configured, a specially crafted request can cause unintended modifications to the target account's properties. This may result in the account being assigned elevated privileges or access beyond what an administrator intended. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-73454
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-73454