External risk intelligence

EOS gRPC Authorization Bypass on OpenConfig

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-73461

The vulnerability affects AAA-based gRPC authorization for OpenConfig on network infrastructure platforms. While gRPC is a network protocol, this management interface is typically restricted to internal administrative segments or protected by management plane access controls, making public internet exposure uncommon in standard deployments.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects network platforms that use gRPC authorization for configuration requests. When improperly configured, authenticated users may be granted unintended access levels through a specific authorization method, though it does not impact other configuration methods like NETCONF. The primary concern is confirming if the affected configuration is in use within your environment.

  • Misconfigured authorization on network devices.
  • Potential for unintended access to network configurations.
  • Confirm relevance and exposure within your network.

Attack Path

How an attacker could exploit the issue

An attacker who has authenticated to an affected EOS platform could potentially leverage the vulnerability to gain elevated privileges. This occurs when gRPC requests for OpenConfig are processed with an incorrect authorization level due to a flaw in how privilege levels are handled, even though other OpenConfig requests are unaffected.

  • Authenticated access required.
  • gRPC OpenConfig requests trigger vulnerability.
  • Potential for elevated privileges.

Live Threat

Current exploitation, exposure, and threat context

When AAA-based gRPC authorization is enabled for OpenConfig on affected EOS platforms, an authenticated user's gRPC requests may be processed with an incorrect privilege level. This could lead to the execution of actions beyond the user's intended access, impacting service behavior. This vulnerability does not affect other OpenConfig request types like NETCONF.

  • Network device configurations.
  • Incorrect AAA authorization.
  • Unauthorized configuration changes.

Operational Fix

Recommended remediation, mitigation, and detection steps

The described vulnerability affects network platforms with AAA-based gRPC authorization for OpenConfig, indicating that infrastructure or network operations teams are likely responsible for remediation. The immediate first step should be to identify all affected devices, confirm their exposure and criticality, and then determine the appropriate ownership for planning the next actions.

  • Infrastructure and network teams own the issue.
  • Verify affected platforms and criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Arista EOS and how does OpenConfig use gRPC?

Arista EOS is a network operating system used to manage high-performance data center and cloud switches. OpenConfig provides a standardized, vendor-neutral way to configure these network devices. gRPC is a modern communication protocol that allows automated systems to send these configurations efficiently. This vulnerability specifically concerns the mechanism that verifies user permissions when using gRPC to push OpenConfig updates to the device.

What is the security weakness behind CVE-2026-73461?

This issue is classified as CWE-266, which refers to incorrect privilege assignment. In this specific scenario, when a user is already authenticated to the system, the device may fail to map their request to the correct security level while processing OpenConfig commands over gRPC. Consequently, the system might grant the user more authority than they should have, allowing them to perform actions that would typically be restricted based on their assigned role.

Do I need to worry about NETCONF requests?

No, this vulnerability does not affect NETCONF. The issue is strictly tied to gRPC-based interactions within the OpenConfig framework. If your infrastructure relies on NETCONF or other configuration methods to manage your network devices, those specific traffic paths are not susceptible to this particular authorization flaw.

Is my device at risk based on Halo Surface Signal?

Halo Surface Signal indicates that while this is a network-based vulnerability, the affected interface is usually isolated. Because OpenConfig over gRPC is a management-plane function, it is typically restricted to internal administrative networks rather than exposed to the public internet. You should confirm whether your specific management segments are truly isolated, as Halo suggests public exposure for this component is uncommon.

How do I start addressing this CVE in my environment?

The first step is to determine if your network devices have AAA-based gRPC authorization enabled specifically for OpenConfig. Coordinate with your infrastructure or network operations teams to audit current device configurations. Once you identify which systems are running this setup, evaluate their criticality to your operations to prioritize your response and plan the necessary configuration updates.

References