CVE-2026-9142 PUBLISHED

Insecure Default Credentials vulnerability in NI grpc-device when TLS configuration is not present

Assigner: NI
Reserved: 20.05.2026 Published: 19.06.2026 Updated: 19.06.2026

There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the server is bound beyond loopback.  This may allow an unauthenticated user access to the server on the local network.  This affects NI grpc-device 2.17.0 and prior versions.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor NI
Product grpc-device
Versions Default: unaffected
  • affected from 0 to 2.17.0 (incl.)
Vendor NI
Product InstrumentStudio
Versions Default: unaffected
  • affected from 0 to 26.3.0 (incl.)

Credits

  • Sebastián Alba Vives (@Sebasteuo / 0xS4bb1) finder

References

Problem Types

  • CWE-306 Missing authentication for critical function CWE

Impacts

  • CAPEC-115 Authentication Bypass