PatchSiren cyber security CVE debrief
CVE-2026-9142 NI CVE debrief
CVE-2026-9142 is a critical insecure default credentials vulnerability in NI grpc-device. When TLS configuration is not present and the server is bound beyond loopback, an unauthenticated user may access the server on the local network. This affects NI grpc-device versions 2.17.0 and prior. The CVSS score is 9.3, indicating a high severity. Defenders should assess their exposure and prioritize patching.
- Vendor
- NI
- Product
- grpc-device
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-19
- Original CVE updated
- 2026-06-25
- Advisory published
- 2026-06-19
- Advisory updated
- 2026-06-25
Who should care
Organizations using NI grpc-device, especially those with servers bound beyond loopback without TLS configuration, should be concerned. This vulnerability could allow unauthorized access on the local network.
Technical summary
The vulnerability exists in NI grpc-device when TLS configuration is not present. If the server is bound beyond loopback, an unauthenticated user could access the server on the local network. The affected versions are 2.17.0 and prior. The CVSS vector is CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X, indicating a critical severity.
Defensive priority
High priority due to high CVSS score and potential for unauthorized access
Recommended defensive actions
- Inventory NI grpc-device installations to identify potential exposure
- Review and apply TLS configuration for grpc-device servers
- Limit server bindings to loopback where possible
- Upgrade to a version of NI grpc-device that is not vulnerable
- Monitor for unauthorized access attempts on the local network
Evidence notes
The primary evidence comes from the CVE record and NVD detail. The vulnerability affects NI grpc-device versions 2.17.0 and prior. Defenders should verify their grpc-device configurations and versions against official documentation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-9142 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-9142
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-9142 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9142
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/ni/grpc-device/security/advisories/GHSA-fhhw-37q8-6562
-
Source reference
Unverified legacy reference
URL: https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/2026/multiple-vulnerabilities-in-ni-grpc-device-server.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.