PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-9142 NI CVE debrief

CVE-2026-9142 is a critical insecure default credentials vulnerability in NI grpc-device. When TLS configuration is not present and the server is bound beyond loopback, an unauthenticated user may access the server on the local network. This affects NI grpc-device versions 2.17.0 and prior. The CVSS score is 9.3, indicating a high severity. Defenders should assess their exposure and prioritize patching.

Vendor
NI
Product
grpc-device
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-19
Original CVE updated
2026-06-25
Advisory published
2026-06-19
Advisory updated
2026-06-25

Who should care

Organizations using NI grpc-device, especially those with servers bound beyond loopback without TLS configuration, should be concerned. This vulnerability could allow unauthorized access on the local network.

Technical summary

The vulnerability exists in NI grpc-device when TLS configuration is not present. If the server is bound beyond loopback, an unauthenticated user could access the server on the local network. The affected versions are 2.17.0 and prior. The CVSS vector is CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X, indicating a critical severity.

Defensive priority

High priority due to high CVSS score and potential for unauthorized access

Recommended defensive actions

  • Inventory NI grpc-device installations to identify potential exposure
  • Review and apply TLS configuration for grpc-device servers
  • Limit server bindings to loopback where possible
  • Upgrade to a version of NI grpc-device that is not vulnerable
  • Monitor for unauthorized access attempts on the local network

Evidence notes

The primary evidence comes from the CVE record and NVD detail. The vulnerability affects NI grpc-device versions 2.17.0 and prior. Defenders should verify their grpc-device configurations and versions against official documentation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-9142 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-9142

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-9142 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9142

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/ni/grpc-device/security/advisories/GHSA-fhhw-37q8-6562

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/2026/multiple-vulnerabilities-in-ni-grpc-device-server.html

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.