Insecure Default Credentials in NI grpc-device Affecting Network Security
CVE-2026-9142

9.3CRITICAL

Key Information:

Vendor

Ni

Vendor
CVE Published:
19 June 2026

What is CVE-2026-9142?

The NI grpc-device is impacted by a vulnerability that arises when TLS configuration is absent and the server is accessible beyond the loopback interface. This flaw enables unauthorized users to potentially gain access to the server on the local network, posing significant security risks. Products affected include versions 2.17.0 and earlier, which should be reviewed and updated promptly to prevent exploitation.

Affected Version(s)

grpc-device 0 <= 2.17.0

InstrumentStudio 0 <= 26.3.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sebastián Alba Vives (@Sebasteuo / 0xS4bb1)
.