Authorization Issue in gRPC.js Affects Service Method Access
CVE-2026-101914

6.5MEDIUM

Key Information:

Vendor

Grpc

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-101914?

The @grpc/grpc-js library, which provides a JavaScript implementation of gRPC without using a C++ add-on, contains an authorization flaw prior to versions 1.13.1 and 1.14.1. The role-based access control (RBAC) implementation incorrectly uses prefix comparison for method names when case-insensitive checks are enabled. This can allow a method with a longer name that prefixes another method's name to inadvertently match the shorter method's access rule, potentially leading to unauthorized access to sensitive functions. To mitigate this risk, it is crucial to update to the patched versions 1.13.1 or 1.14.1.

Affected Version(s)

grpc-node < 1.13.1 < 1.13.1

grpc-node >= 1.14.0, < 1.14.1 < 1.14.0, 1.14.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.