Back

HIGH

Security Advisory 0166

Published Sep 16, 2026

Description

On affected platforms running Arista EOS with gRPC Network Management Interface (gNMI) enabled, a specially crafted request could allow a malicious authenticated client with gRPC Network Management Interface (gNMI) access to execute arbitrary code with root privileges on the switch.

Affected products

Remediation

Vendor solution

The following EOS releases contain the fix for this vulnerability: - 4.33.9M and later releases in the 4.33.x train - 4.34.7.1M and later releases in the 4.34.x train - 4.35.6M and later releases in the 4.35.x train - 4.36.1F and later releases in the 4.36.x train

No hotfix is available for this vulnerability.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Arista
Published Sep 16, 2026
Updated Sep 17, 2026
Reserved Aug 12, 2026
CISA Vulnrichment
Updated Sep 16, 2026
NVD
Status Awaiting Analysis
Modified Sep 17, 2026
Red Hat
Severity n/a
Public date n/a