Description
Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch.
Published: 2026-09-16
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

An arbitrary code execution flaw exists in Arista EOS when gNPSI is enabled. An unauthenticated attacker can craft a malicious request that triggers execution of arbitrary code, giving full administrative control over the switch. The root weakness is identified as CWE-94, a command injection type flaw that compromises confidentiality, integrity and availability.

Affected Systems

Arista Networks EOS systems are vulnerable, specifically any EOS release that does not incorporate the 4.36.2F, 4.35.6M or 4.34.8M fixes and is running gNPSI. The advisory notes that the vulnerability affects all earlier releases of the 4.36.x, 4.35.x and 4.34.x train versions where gNPSI is active.

Risk and Exploitability

The CVSS score of 9.2 marks this as a critical issue, while the EPSS score of less than 1% indicates a low exploitation probability at present and it is not listed in the CISA KEV catalog. The attack vector relies on the gRPC interface provided by gNPSI, which is unauthenticated by default. Any host with network reach to the management interface can send the crafted request and immediately gain root access to the device.

Generated by OpenCVE AI on September 18, 2026 at 01:01 UTC.

Remediation

Vendor Solution

The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73456 has been fixed in the following releases: * 4.36.2F and later releases in the 4.36.x train * 4.35.6M and later releases in the 4.35.x train * 4.34.8M and later releases in the 4.34.x train


Vendor Workaround

To secure the agent against CVE-2026-73456, configure the service to use mutual TLS and enable only x509-spiffe authentication: management security ssl profile P1 certificate server.crt key server.key trust certificate ca_client.crt chain certificate ca_signing.crt ! management api gnpsi transport grpc t2 ssl profile P1 port 7001 authentication username priority x509-spiffe no disabled


OpenCVE Recommended Actions

  • Upgrade EOS to any of the patched releases: 4.36.2F or later, 4.35.6M or later, or 4.34.8M or later. This eliminates the vulnerability without further reconfiguration. ,
  • If an upgrade cannot be performed immediately, enforce mutual TLS and x509‑spiffe authentication on the gNPSI service as demonstrated in the advisory: configure an SSL profile that attests to the client’s spiffe identity, enable the profile on the gRPC transport, and disable any anonymous or basic authentication options. This mitigates the unauthenticated entry point that the exploit requires. ,
  • As a separate hardening measure, block or remove the gNPSI service from the switch or close port 7001 at the network perimeter. Disabling the service removes the vulnerable surface area entirely and prevents any potential exploitation through gNPSI.

Generated by OpenCVE AI on September 18, 2026 at 01:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Arista
Arista eos
Vendors & Products Arista
Arista eos

Wed, 16 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch.
Title Under certain circumstances, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch.
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-17T11:39:23.874Z

Reserved: 2026-08-12T16:45:03.510Z

Link: CVE-2026-73456

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T19:17:32.270

Modified: 2026-09-17T12:18:25.887

Link: CVE-2026-73456

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:51:24Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')