Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch.
In order to be vulnerable to CVE-2026-73456, gNPSI must be enabled and one of the following conditions must be met:
- A gNPSI transport is configured to perform TLS (server verification) and metadata authentication is enabled:
switch> show management api gnpsi
Transport: t2
Enabled: yes
Server: running on port 7001
Source: sflow
Listening VRF default: ::
SSL profile: P2, TLS configured
Authentication username priority: x509-spiffe, metadata, x509-common-name
- Or mTLS is enabled with x509-common-name authentication configured:
switch> show management api gnpsi
Transport: t2
Enabled: yes
Server: running on port 7001
Source: sflow
Listening VRF default: ::
SSL profile: P2, mutual TLS configured
Authentication username priority: x509-spiffe, x509-common-name
Systems remain unaffected if gNPSI is not enabled (default configuration):
switch> show management api gnpsi
Enabled: no transports enabled
To secure the agent against CVE-2026-73456, configure the service to use mutual TLS and enable only x509-spiffe authentication:
management security
ssl profile P1
certificate server.crt key server.key
trust certificate ca_client.crt
chain certificate ca_signing.crt
!
management api gnpsi
transport grpc t2
ssl profile P1
port 7001
authentication username priority x509-spiffe
no disabled
The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73456 has been fixed in the following releases:
- 4.36.2F and later releases in the 4.36.x train
- 4.35.6M and later releases in the 4.35.x train
- 4.34.8M and later releases in the 4.34.x train