Improper privilege management in Arista Extensible Operating System (EOS) - CVE-2026-52897

 

Improper privilege management in Arista Extensible Operating System (EOS) - CVE-2026-52897

Published: June 24, 2026


Vulnerability identifier: #VU135097
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-52897
CWE-ID: CWE-269
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform unauthorized operations.

The vulnerability exists due to improper privilege management in user privilege handling on the device when authenticated users access the system. A local user can obtain privilege levels that exceed intended restrictions to perform unauthorized operations.

The agent must be configured to stream to CloudVision for exploitation.


Affected software

Arista Extensible Operating System (EOS)

How to mitigate CVE-2026-52897

Install security update from vendor's website.

Arista Extensible Operating System (EOS) - addressed in versions 4.33.9M, 4.34.8M, 4.35.6M, 4.36.1F

External References

Related Security Bulletins