CVE-2026-19640
4.2 MEDIUMPublished 2026-09-16 · Updated 2026-09-16
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
On affected platforms running Arista EOS, an authenticated user with access to the gNMI (gRPC Network Management Interface) may receive incorrect authorization results, potentially allowing access beyond their currently assigned permissions. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Weaknesses
CWE-863
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-1242
- MEDIUMCVE-2026-18773PoC
- UNSCOREDCVE-2026-52740PoC
- UNSCOREDCVE-2026-52742PoC
- MEDIUMCVE-2026-52743PoC
- LOWCVE-2026-55060PoC
- UNSCOREDCVE-2026-55563PoC
- MEDIUMCVE-2026-55625PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.