OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-73447

CRITICAL · CVSS 9.1 EPSS 0.70% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-16 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

A critical vulnerability allows authenticated users to exploit the gRPC Network Security Interface (gNSI) Certz service on Arista EOS-based products, enabling them to escalate privileges and execute arbitrary OS commands with root access. This could lead to complete device compromise, making it imperative for organizations using Arista EOS systems to prioritize patching and remediation efforts. Security teams should focus on monitoring and securing their environments against potential exploitation of this vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-73447
Severity
CRITICAL
CVSS
9.1
EPSS
0.70%

Original NVD Description

A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full device compromise. An authenticated user can exploit gRPC Network Security Interface (gNSI) Certz service on Arista EOS-based products to escalate privileges and execute arbitrary OS commands via a crafted Certz Rotate request. The Bootz service is also affected.