Loading market data...
← Back to CVE feed

CVE-2026-19640

MEDIUM CVSS 4.2 View on NVD ↗

Description

On affected platforms running Arista EOS, an authenticated user with access to the gNMI (gRPC Network Management Interface) may receive incorrect authorization results, potentially allowing access beyond their currently assigned permissions. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Published: Sep 16, 2026 10:16 UTC Modified: Sep 16, 2026 19:08 UTC